Логотип exploitDog
bind:CVE-2021-21087
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-21087

Количество 3

Количество 3

nvd логотип

CVE-2021-21087

почти 5 лет назад

Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An attacker could abuse this vulnerability to execute arbitrary JavaScript code in context of the current user. Exploitation of this issue requires user interaction.

CVSS3: 5.4
EPSS: Высокий
github логотип

GHSA-9mx8-9vhh-5qr7

больше 3 лет назад

Adobe Coldfusion versions 2016 (update 16 and earlier) and 2018 (update 10 and earlier) are affected by an Improper Neutralization of Directives in Dynamically Evaluated Code (‘Eval Injection’) vulnerability. An attacker could abuse this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction.

CVSS3: 5.4
EPSS: Высокий
fstec логотип

BDU:2021-02544

почти 5 лет назад

Уязвимость программной платформы ColdFusion, связанная c непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный код

CVSS3: 8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-21087

Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An attacker could abuse this vulnerability to execute arbitrary JavaScript code in context of the current user. Exploitation of this issue requires user interaction.

CVSS3: 5.4
84%
Высокий
почти 5 лет назад
github логотип
GHSA-9mx8-9vhh-5qr7

Adobe Coldfusion versions 2016 (update 16 and earlier) and 2018 (update 10 and earlier) are affected by an Improper Neutralization of Directives in Dynamically Evaluated Code (‘Eval Injection’) vulnerability. An attacker could abuse this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction.

CVSS3: 5.4
84%
Высокий
больше 3 лет назад
fstec логотип
BDU:2021-02544

Уязвимость программной платформы ColdFusion, связанная c непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный код

CVSS3: 8
84%
Высокий
почти 5 лет назад

Уязвимостей на страницу