adobe.comConfirmation
http://www.adobe.com/support/security/bulletins/apsb13-27.html CVE-2013-5326
Adobe ColdFusion Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2013-5326 has a selected CVSS score of 3.5.
Description
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0 before Update 12, 9.0.1 before Update 11, 9.0.2 before Update 6, and 10 before Update 12, when the CFIDE directory is available, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the logviewer directory.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 29, 2016 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ColdFusionBrowse Adobe / ColdFusion | VulnCheck | Version data not supplied | |
References
3VU#295276Third-party advisory
http://www.kb.cert.org/vuls/id/295276 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-5326