HomePentest-Tools.com Logo

Adobe ColdFusion 8.0/8.0.1/9.0/9.0.1 LFI CVE-2010-2861

Severity
CVSSv3 Score
7.5
Vulnerability description

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.

Risk description

The risk exists that a remote unauthenticated attacker could exploit this vulnerability to read sensitive information from arbitrary files located on the file system of the server.

Recommendation

Upgrade to the latest version to mitigate this vulnerability.

Codename
Not available
Detectable with
Network Scanner
Scan engine
Nuclei
Exploitable with Sniper
No
CVE Published
Aug 11, 2010
Detection added at
Software Type
Not available
Vendor
Not available
Product
Not available