Back
CVE-2002-1700
Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.
Published: Dec 31, 2002
Modified: Jun 16, 2026
CWE-79
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| macromedia | coldfusion | 6.0 |
| microsoft | internet_information_services | 5.0 |
| microsoft | windows_2000 | * |
GitHub Security Advisory GHSA-r8f7-hhg3-c763
Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion...
References (8)
- http://online.securityfocus.com/archive/1/277487
- http://www.macromedia.com/v1/Handlers/index.cfm?ID=23047
- http://www.securityfocus.com/bid/5011
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9360
- http://online.securityfocus.com/archive/1/277487
- http://www.macromedia.com/v1/Handlers/index.cfm?ID=23047
- http://www.securityfocus.com/bid/5011
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9360
Risk Scores
CVSS Score
4.3 / 10
EPSS Score
22.90%
Top 2% most likely to be exploited
Threat Score
24.1 / 100
Data Sources
NVD
EPSS
GitHub