Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.804445
Kategorie:Web application abuses
Titel:Adobe ColdFusion Multiple Vulnerabilities (APSB13-03)
Zusammenfassung:Adobe ColdFusion is prone to multiple vulnerabilities.
Beschreibung:Summary:
Adobe ColdFusion is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- The CFIDE/componentutils/cfcexplorer.cfc script not properly sanitizing
user input, specifically directory traversal attacks supplied via the
'path' parameter when 'method' is set to:'getcfcinhtml' and 'name' is
set to 'CFIDE.adminapi.administrator'.

- The 'ScheduledURL' variable allows specifying an arbitrary resource to save
to system as specified by the 'publish_file' variable and then schedule this
task to be executed at a set time.

Vulnerability Impact:
Successful exploitation will allow attackers to disclose the contents of
arbitrary files on the system and execute arbitrary code.

Affected Software/OS:
Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10.

Solution:
Apply the patch from the referenced advisory.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: BugTraq ID: 57164
BugTraq ID: 57165
Common Vulnerability Exposure (CVE) ID: CVE-2013-0625
http://www.securityfocus.com/bid/57164
Common Vulnerability Exposure (CVE) ID: CVE-2013-0629
http://www.securityfocus.com/bid/57165
CopyrightCopyright (C) 2014 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.