Page 2 of 28 results (0.004 seconds)

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 0

Adobe (formerly Macromedia) ColdFusion MX 7.0 exposes the password hash of the Administrator in an API call, which allows local developers to obtain the hash and gain privileges. Adobe (antes Macromedia) ColdFusion MX 7.0 expone la huella digital ('hash') de la contraseña de administrador en una llamada API, lo que permite a desarrolladores locales obtener la huella digital y ganar privilegios. • http://secunia.com/advisories/18078 http://securitytracker.com/id?1015371 http://www.macromedia.com/devnet/security/security_zone/mpsb05-14.html http://www.securityfocus.com/bid/15904 http://www.vupen.com/english/advisories/2005/2948 •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the "?" (question mark) character. ColdFusion Fusebox 4.1.0 permite que atacantes remotos obtengan información confidencial mediante un parámetro fuseaction inválido. • http://marc.info/?l=bugtraq&m=112309656102615&w=2 •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 2

Cross-site scripting (XSS) vulnerability in ColdFusion Fusebox 4.1.0 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter, which is not quoted in an error page, as demonstrated using index.cfm. Vulnerabilidad de secuencias de comandos en sitios cruzados en ColdFusion Fusebox 4.1.0 permite que atacantes remotos inyecten script web arbitrario o HTML (mediante el parámetro fuseaction). • https://www.exploit-db.com/exploits/26065 http://marc.info/?l=bugtraq&m=112309656102615&w=2 http://secunia.com/advisories/16320 http://www.securityfocus.com/bid/14460 https://exchange.xforce.ibmcloud.com/vulnerabilities/21697 •

CVSS: 3.7EPSS: 0%CPEs: 3EXPL: 0

Race condition in Macromedia JRun 4.0, ColdFusion MX 6.1 and 7.0, when under heavy load, causes JRun to assign a duplicate authentication token to multiple sessions, which could allow authenticated users to gain privileges as other users. "Race condition" en Macromedia JRun 4.0, ColdFusion MX 6.1 y 7.0 cuando están bajo carga pesada, provocan que JRun asigne una autentifcación duplicada a sesiones múltiples, lo que podría permitir que usuarios autentificados obtengan privilegios como otros usuarios. • http://secunia.com/advisories/16081 http://securitytracker.com/id?1014489 http://www.macromedia.com/devnet/security/security_zone/mpsb05-05.html •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page. • http://marc.info/?l=bugtraq&m=111575500403231&w=2 http://www.macromedia.com/devnet/security/security_zone/mpsb05-03.html https://exchange.xforce.ibmcloud.com/vulnerabilities/20550 •