.. / CVE-2009-1872

Exploit for Adobe Coldfusion <=8.0.1 - Cross-Site Scripting (CVE-2009-1872)

Description:

Adobe ColdFusion Server 8.0.1 and earlier contain multiple cross-site scripting vulnerabilities which allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.

Nuclei Template

View the template here CVE-2009-1872.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2009/CVE-2009-1872.yaml
Copy

References:

http://www.dsecrg.com/pages/vul/show.php?id=122
https://www.tenable.com/cve/CVE-2009-1872
https://github.com/ARPSyndicate/kenzer-templates
https://nvd.nist.gov/vuln/detail/CVE-2009-1872
http://www.adobe.com/support/security/bulletins/apsb09-12.html