Описание
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.
Ссылки
- MitigationVendor Advisory
- Broken LinkVendor Advisory
- ExploitThird Party AdvisoryVDB Entry
- MitigationVendor Advisory
- Broken LinkVendor Advisory
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Одно из
EPSS
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
Связанные уязвимости
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.
Уязвимость компонента administrator.cfc веб-интерфейса программной платформы ColdFusio, позволяющая нарушителю обойти ограничения безопасности или выполнить произвольный код
EPSS
9.8 Critical
CVSS3
10 Critical
CVSS2