Vulnerability Description
Cross-site scripting (XSS) vulnerability in ColdFusion Fusebox 4.1.0 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter, which is not quoted in an error page, as demonstrated using index.cfm.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Macromedia | Coldfusion Fusebox | 4.1.0 |
References
- http://marc.info/?l=bugtraq&m=112309656102615&w=2
- http://secunia.com/advisories/16320Vendor Advisory
- http://www.securityfocus.com/bid/14460Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21697
- http://marc.info/?l=bugtraq&m=112309656102615&w=2
- http://secunia.com/advisories/16320Vendor Advisory
- http://www.securityfocus.com/bid/14460Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21697
FAQ
What is CVE-2005-2480?
CVE-2005-2480 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in ColdFusion Fusebox 4.1.0 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter, which is not quoted in an error page, ...
How severe is CVE-2005-2480?
CVE-2005-2480 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-2480?
Check the references section above for vendor advisories and patch information. Affected products include: Macromedia Coldfusion Fusebox.