CVE-2016-4159
16.06.2016, 14:59
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 20, 11 before Update 9, and 2016 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
| Vendor | Product | Version |
|---|---|---|
| adobe | coldfusion | 10.0 |
| adobe | coldfusion | 10.0:update1 |
| adobe | coldfusion | 10.0:update10 |
| adobe | coldfusion | 10.0:update11 |
| adobe | coldfusion | 10.0:update12 |
| adobe | coldfusion | 10.0:update13 |
| adobe | coldfusion | 10.0:update14 |
| adobe | coldfusion | 10.0:update15 |
| adobe | coldfusion | 10.0:update16 |
| adobe | coldfusion | 10.0:update17 |
| adobe | coldfusion | 10.0:update18 |
| adobe | coldfusion | 10.0:update19 |
| adobe | coldfusion | 10.0:update2 |
| adobe | coldfusion | 10.0:update3 |
| adobe | coldfusion | 10.0:update4 |
| adobe | coldfusion | 10.0:update5 |
| adobe | coldfusion | 10.0:update6 |
| adobe | coldfusion | 10.0:update7 |
| adobe | coldfusion | 10.0:update8 |
| adobe | coldfusion | 10.0:update9 |
| adobe | coldfusion | 11.0 |
| adobe | coldfusion | 11.0:update1 |
| adobe | coldfusion | 11.0:update2 |
| adobe | coldfusion | 11.0:update3 |
| adobe | coldfusion | 11.0:update4 |
| adobe | coldfusion | 11.0:update5 |
| adobe | coldfusion | 11.0:update6 |
| adobe | coldfusion | 11.0:update7 |
| adobe | coldfusion | 11.0:update8 |
𝑥
= Vulnerable software versions