← Back

CVE-2013-5326

nvd nist
Published: Nov 13, 2013Modified: Apr 29, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0 before Update 12, 9.0.1 before Update 11, 9.0.2 before Update 6, and 10 before Update 12, when the CFIDE directory is available, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the logviewer directory.

Affected (10)

Products: Adobe: Coldfusion
1 product
Coldfusion
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Version 9.0.1
Version 9.0.2
Version 9.0
Configuration B
7 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Up to 10.0
Version 10.0
Version 10.0 update1
Version 10.0 update2
Version 10.0 update3
Version 10.0 update4
Version 10.0 update8

References (4)

Source: psirt@adobe.com
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource

Timeline

No history available yet.