Back

CVE-2002-1700

Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.

Published: Dec 31, 2002 Modified: Jun 16, 2026
CWE-79

CVSS Metrics

Affected Products (3)

Vendor Product Version
macromedia coldfusion 6.0
microsoft internet_information_services 5.0
microsoft windows_2000 *

GitHub Security Advisory GHSA-r8f7-hhg3-c763

Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion...

Risk Scores

CVSS Score 4.3 / 10
EPSS Score 22.90%

Top 2% most likely to be exploited

Threat Score 24.1 / 100

Data Sources

NVD EPSS GitHub