[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195521

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Multiple directory traversal vulnerabilities in Adobe ColdFusion - APSB10-18

ID: oval:org.secpod.oval:def:9454Date: (C)2013-03-01   (M)2022-10-10
Class: PATCHFamily: unix




The host is missing an important security update according to Adobe security bulletin, APSB10-18. The update is required to fix multiple directory traversal vulnerabilities. The flaws are present due to error in the administrator console which are CFIDE/administrator/settings/mappings.cfm, logging/settings.cfm, datasources/index.cfm, j2eepackaging/editarchive.cfm, and enter.cfm in CFIDE/administrator/. Successful exploitation allows remote attackers to read arbitrary files via the locale parameter.

Platform:
Linux
Product:
Adobe ColdFusion
Reference:
APSB10-18
CVE-2010-2861
CVE    1
CVE-2010-2861
CPE    7
cpe:/a:adobe:coldfusion
cpe:/a:adobe:coldfusion:9.0.0.0
cpe:/a:adobe:coldfusion:9.0
cpe:/a:adobe:coldfusion:9.0.1
...

© SecPod Technologies