← Back

CVE-2016-4159

nvd nist
Published: Jun 16, 2016Modified: May 6, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 20, 11 before Update 9, and 2016 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected (31)

Products: Adobe: Coldfusion
1 product
Coldfusion
Configuration A
31 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Version 10.0
Version 10.0 update10
Version 10.0 update11
Version 10.0 update12
Version 10.0 update13
Version 10.0 update14
Version 10.0 update15
Version 10.0 update16
Version 10.0 update17
Version 10.0 update18
Version 10.0 update19
Version 10.0 update1
Version 10.0 update2
Version 10.0 update3
Version 10.0 update4
Version 10.0 update5
Version 10.0 update6
Version 10.0 update7
Version 10.0 update8
Version 10.0 update9
Version 11.0
Version 11.0 update1
Version 11.0 update2
Version 11.0 update3
Version 11.0 update4
Version 11.0 update5
Version 11.0 update6
Version 11.0 update7
Version 11.0 update8
Version 2016
Version 2016 update1

References (4)

Source: psirt@adobe.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.