Page 5 of 90 results (0.005 seconds)

CVSS: 7.8EPSS: 0%CPEs: 7EXPL: 0

Adobe ColdFusion 10 before Update 12 allows remote attackers to read arbitrary files via unspecified vectors. Adobe ColdFusion 10 anterior a Update 12 permite a atacantes remotos leer ficheros arbitrarios a través de vectores sin especificar • http://www.adobe.com/support/security/bulletins/apsb13-27.html • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 10.0EPSS: 0%CPEs: 3EXPL: 0

The authentication process in Adobe ColdFusion before 10 does not require knowledge of the cleartext password if the password hash is known, which makes it easier for context-dependent attackers to obtain administrative privileges by leveraging read access to the configuration file, a different vulnerability than CVE-2010-2861. El proceso de autenticación en Adobe ColdFusion anteriores a v10 no requiere conocimiento de la contraseña en claro si el hash de la contraseña es conocido, lo cual facilita a atacantes dependientes del contexto obtener privilegios administrativos aprovechando el acceso de lectura al fichero de configuración, una vulnerabilidad distinta a CVE-2010-2861. • http://osvdb.org/97553 http://qualys.immunityinc.com/home/exploitpack/CANVAS/CF_directory_traversal http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861 https://exchange.xforce.ibmcloud.com/vulnerabilities/87740 • CWE-255: Credentials Management Errors •

CVSS: 5.0EPSS: 0%CPEs: 6EXPL: 0

Unspecified vulnerability in Adobe ColdFusion 10 and earlier allows attackers to cause a denial of service via unknown vectors. Vulnerabilidad no especificada en Adobe ColdFusion 10 y anteriores permite a atacantes provocar una denegación de servicio a través de vectores desconocidos. • http://osvdb.org/85317 http://secunia.com/advisories/50523 http://www.adobe.com/support/security/bulletins/apsb12-21.html http://www.securitytracker.com/id?1027516 https://exchange.xforce.ibmcloud.com/vulnerabilities/78410 •

CVSS: 4.3EPSS: 2%CPEs: 3EXPL: 0

CRLF injection vulnerability in the Component Browser in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. Vulnerabilidad de inyección CRLF en el navegador de componente de Adobe ColdFusion 8.0 hasta la versión 9.0.1. Permite a atacantes remotos inyectar cabeceras HTTP arbitrarias y realizar ataques de división de respuestas HTTP a través de vectores sin especificar. • http://www.adobe.com/support/security/bulletins/apsb12-15.html • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 5.0EPSS: 1%CPEs: 4EXPL: 0

Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. Adobe ColdFusion v8.0, v8.0.1, v9.0 y v9.0.1, calcula los valores hash de los parámetros del formulario sin restringir la capacidad de desencadenar colisiones de hash predecibles, lo que permite a atacantes remotos provocar una denegación de servicio (consumo de CPU) mediante el envío de muchos parámetros modificados. • http://helpx.adobe.com/coldfusion/kb/coldfusion-security-hotfix.html http://osvdb.org/80008 http://secunia.com/advisories/48393 http://www.adobe.com/support/security/bulletins/apsb12-06.html http://www.securitytracker.com/id?1026830 https://exchange.xforce.ibmcloud.com/vulnerabilities/73955 •