Description
Railo is an open-source alternative to the popular Coldfusion application server, implementing a FOSSy CFML engine and application server. Multiple critical vulnerabilities were reported in this application server. This test has confirmed a cross-site scripting vulnerability in the administration panel.
Remediation
Upgrade to the latest version of Railo.
References
Related Vulnerabilities
WordPress Plugin Form Builder-Create Responsive Contact Forms Cross-Site Scripting (1.9.8.4)
WordPress Plugin WP eCommerce Cross-Site Scripting (3.9.2)
WordPress Plugin Ultimate Maps by Supsystic Cross-Site Scripting (1.2.4)
WordPress Plugin Local Market Explorer 'api-key' Parameter Cross-Site Scripting (3.1.1)