Friday, 23 June 2006by
Adrian Pastor
ColdFusion Debug-Mode XSS and HTML Injection
Coldfusion's debug mode, when enabled via appending "mode=debug" to URLs, is vulnerable to XSS and HTML injection attacks, a risk not widely report ....
