Description
Railo is an open-source alternative to the popular Coldfusion application server, implementing a FOSSy CFML engine and application server. Multiple critical vulnerabilities were reported in this application server. This test has confirmed a cross-site scripting vulnerability in the administration panel.
Remediation
Upgrade to the latest version of Railo.
References
Related Vulnerabilities
WordPress Plugin Gallery Categories by BestWebSoft Cross-Site Scripting (1.0.8)
WordPress Plugin WP Social Sharing Cross-Site Scripting (2.2)
WordPress Plugin FV Flowplayer Video Player Cross-Site Scripting (7.3.13.727)
WordPress Plugin Job Board Vanila Cross-Site Scripting (1.0)
WordPress Plugin Stock in & out Cross-Site Scripting (1.0.4)