CVE-2006-5859
Adobe Coldfusion - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 7.0 and 7.0.1, when Global Script Protection is not enabled, allows remote attackers to inject arbitrary HTML and web script via unknown vectors, possibly related to Linkdirect.cfm, Topnav.cfm, and Welcomedoc.cfm.
References (6)
Scores
EPSS
0.0244
EPSS Percentile
85.0%
Classification
CWE
CWE-79
Status
draft
Affected Products (2)
adobe/coldfusion
adobe/coldfusion
Timeline
Published
Feb 14, 2007
Tracked Since
Feb 18, 2026