← Back

CVE-2002-1700

nvd nist
Published: Dec 31, 2002Modified: Apr 16, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.

Affected (3)

1 product
Coldfusion
2 products
Internet Information Services
Windows 2000
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.0
Version 5.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (8)

Timeline

No history available yet.