Page 5 of 49 results (0.004 seconds)

CVSS: 7.8EPSS: 0%CPEs: 7EXPL: 0

Adobe ColdFusion 10 before Update 12 allows remote attackers to read arbitrary files via unspecified vectors. Adobe ColdFusion 10 anterior a Update 12 permite a atacantes remotos leer ficheros arbitrarios a través de vectores sin especificar • http://www.adobe.com/support/security/bulletins/apsb13-27.html • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 10.0EPSS: 0%CPEs: 3EXPL: 0

The authentication process in Adobe ColdFusion before 10 does not require knowledge of the cleartext password if the password hash is known, which makes it easier for context-dependent attackers to obtain administrative privileges by leveraging read access to the configuration file, a different vulnerability than CVE-2010-2861. El proceso de autenticación en Adobe ColdFusion anteriores a v10 no requiere conocimiento de la contraseña en claro si el hash de la contraseña es conocido, lo cual facilita a atacantes dependientes del contexto obtener privilegios administrativos aprovechando el acceso de lectura al fichero de configuración, una vulnerabilidad distinta a CVE-2010-2861. • http://osvdb.org/97553 http://qualys.immunityinc.com/home/exploitpack/CANVAS/CF_directory_traversal http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861 https://exchange.xforce.ibmcloud.com/vulnerabilities/87740 • CWE-255: Credentials Management Errors •

CVSS: 5.0EPSS: 0%CPEs: 6EXPL: 0

Unspecified vulnerability in Adobe ColdFusion 10 and earlier allows attackers to cause a denial of service via unknown vectors. Vulnerabilidad no especificada en Adobe ColdFusion 10 y anteriores permite a atacantes provocar una denegación de servicio a través de vectores desconocidos. • http://osvdb.org/85317 http://secunia.com/advisories/50523 http://www.adobe.com/support/security/bulletins/apsb12-21.html http://www.securitytracker.com/id?1027516 https://exchange.xforce.ibmcloud.com/vulnerabilities/78410 •

CVSS: 4.3EPSS: 2%CPEs: 13EXPL: 3

Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via an id parameter containing a JavaScript onLoad event handler for a BODY element, related to a "tag body" attack. NOTE: this was originally reported as affecting 9.0.1 CHF1 and earlier. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en Adobe ColdFusion v9.0.1 CHF1 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de un parámetro id que contiene un controlador de evento onLoad de JavaScript para un elemento BODY, relacionado con un ataque de "etiqueta body". • http://archives.neohapsis.com/archives/fulldisclosure/2011-01/0537.html http://kb2.adobe.com/cps/890/cpsid_89094.html http://osvdb.org/70778 http://securitytracker.com/id?1025012 http://websecurity.com.ua/4879 http://www.adobe.com/support/security/bulletins/apsb11-04.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.3EPSS: 0%CPEs: 13EXPL: 2

Adobe ColdFusion 9.0.1 CHF1 and earlier allows remote attackers to obtain sensitive information via an id=- query to a .cfm file, which reveals the installation path in an error message. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure ** DISPUTADA ** Adobe ColdFusion 9.0.1 CHF1 y anteriores permite a atacantes remotos obtener información sensible a través de una consulta id=- a un fichero .cfm, lo que revela la ruta de instalación en un mensaje de error. NOTA: El proveedor disputa el significado de este problema porque las secciones Site-wide Error Handler y Debug Output Settings de la guía ColdFusion Lockdown explican el requisito para las configuraciones que evitan la divulgación de esta información. • http://archives.neohapsis.com/archives/fulldisclosure/2011-01/0537.html http://osvdb.org/70781 http://websecurity.com.ua/4879 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •