Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-5290

Опубликовано: 20 сент. 2013
Источник: nvd
CVSS2: 10
EPSS Низкий

Описание

The authentication process in Adobe ColdFusion before 10 does not require knowledge of the cleartext password if the password hash is known, which makes it easier for context-dependent attackers to obtain administrative privileges by leveraging read access to the configuration file, a different vulnerability than CVE-2010-2861.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*:*
Версия до 9.0.2 (включая)
cpe:2.3:a:adobe:coldfusion:9.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:9.0.1:*:*:*:*:*:*:*

EPSS

Процентиль: 81%
0.01616
Низкий

10 Critical

CVSS2

Дефекты

CWE-255

Связанные уязвимости

github
больше 3 лет назад

The authentication process in Adobe ColdFusion before 10 does not require knowledge of the cleartext password if the password hash is known, which makes it easier for context-dependent attackers to obtain administrative privileges by leveraging read access to the configuration file, a different vulnerability than CVE-2010-2861.

EPSS

Процентиль: 81%
0.01616
Низкий

10 Critical

CVSS2

Дефекты

CWE-255