Multiple CRLF injection vulnerabilities in Adobe ColdFusion 8.0 through 9.0.1 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified tags.
| Software | From | Fixed in |
|---|---|---|
| adobe / coldfusion | 8.0 | 8.0.x |
| adobe / coldfusion | 9.0 | 9.0.x |
| adobe / coldfusion | 8.0.1 | 8.0.1.x |
| adobe / coldfusion | 9.0.1 | 9.0.1.x |