Unrated severityNVD Advisory· Published Dec 14, 2011· Updated Apr 29, 2026
CVE-2011-2463
CVE-2011-2463
Description
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving the cfform tag.
Affected products
5cpe:2.3:a:adobe:coldfusion:8.0:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:adobe:coldfusion:8.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:8.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:9.0:*:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:9.0.1:*:*:*:*:*:*:*
- (no CPE)range: 8.0 - 9.0.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.adobe.com/support/security/bulletins/apsb11-29.htmlnvdPatchVendor Advisory
- www.securitytracker.com/idnvd
News mentions
0No linked articles in our index yet.