Vulnerability Note VU#295276

Adobe ColdFusion is vulnerable to cross-site scripting via the logviewer directory

Original Release date: 18 Nov 2013 | Last revised: 22 Nov 2013

Overview

Adobe ColdFusion 10 update 11 and possibly earlier versions contain a reflected cross-site scripting (XSS) (CWE-79) vulnerability.

Description

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Adobe ColdFusion 10 update 11 and possibly earlier versions contains a reflected cross-site scripting (XSS) vulnerability. An attacker can inject arbitrary HTML content (including script) within the /logviewer/ directory.

The vulnerability requires using a relative path, although there is no directory traversal vulnerability.

Impact

A remote unauthenticated attacker can conduct a cross-site scripting attack, which may be used to result in information leakage, privilege escalation, and/or denial of service.

Solution

Adobe has posted an advisory which advises users to apply the appropriate hotfix to their version of ColdFusion to address these vulnerabilities.

Vendor Information (Learn More)

VendorStatusDate NotifiedDate Updated
AdobeAffected22 May 201323 Jul 2013
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)

Group Score Vector
Base 4.3 AV:N/AC:M/Au:N/C:P/I:N/A:N
Temporal 3.4 E:POC/RL:OF/RC:C
Environmental 0.9 CDP:ND/TD:L/CR:ND/IR:ND/AR:ND

References

Credit

Thanks to Tenable Network Security for reporting this vulnerability.

This document was written by Adam Rauf.

Other Information

  • CVE IDs: CVE-2013-5326
  • Date Public: 15 Nov 2013
  • Date First Published: 18 Nov 2013
  • Date Last Updated: 22 Nov 2013
  • Document Revision: 38

Feedback

If you have feedback, comments, or additional information about this vulnerability, please send us email.