Page 7 of 57 results (0.008 seconds)

CVSS: 10.0EPSS: 97%CPEs: 4EXPL: 4

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013. En el archivo administrator.cfc en ColdFusion de Adobe versiones 9.0, 9.0.1, 9.0.2 y 10, permite a los atacantes remotos omitir la autenticación y posiblemente ejecutar código arbitrario mediante el inicio de sesión en el componente RDS con el valor de contraseña vacía por defecto y aprovechando esta sesión para acceder a la interfaz web administrativa, como se explotó “in the wild” en Enero de 2013. An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access. • https://www.exploit-db.com/exploits/30210 https://www.exploit-db.com/exploits/24946 https://www.exploit-db.com/exploits/27755 http://www.adobe.com/support/security/advisories/apsa13-01.html http://www.adobe.com/support/security/bulletins/apsb13-03.html http://www.exploit-db.com/exploits/30210 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.8EPSS: 63%CPEs: 4EXPL: 1

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013. Adobe ColdFusion v9.0, v9.0.1, v9.0.2 y v10, cuando una contraseña no está configurada, permite a atacantes remotos evitar la autenticación y posiblemente ejecutar código arbitrario a través de vectores no especificados, como se explotó en enero de 2013. Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access. • https://www.exploit-db.com/exploits/24946 http://www.adobe.com/support/security/advisories/apsa13-01.html http://www.adobe.com/support/security/bulletins/apsb13-03.html http://www.securityfocus.com/bid/57164 • CWE-255: Credentials Management Errors •

CVSS: 4.3EPSS: 92%CPEs: 4EXPL: 1

Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild in January 2013. Adobe ColdFusion v9.0, v9.0.1, v9.0.2 y v10, cuando una contraseña no está configurada, permite a los atacantes acceder a directorios restringidos a través de vectores no especificados, como se explotó en enero de 2013. Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories. • https://www.exploit-db.com/exploits/24946 http://www.adobe.com/support/security/advisories/apsa13-01.html http://www.adobe.com/support/security/bulletins/apsb13-03.html http://www.securityfocus.com/bid/57165 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 5.0EPSS: 82%CPEs: 3EXPL: 0

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in January 2013. Adobe ColdFusion v9.0, v9.0.1, y v9.0.2 permite a los atacantes obtener información sensible a través de vectores no especificados, como se explotó en enero de 2013. Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server. • http://www.adobe.com/support/security/advisories/apsa13-01.html http://www.adobe.com/support/security/bulletins/apsb13-03.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 4.4EPSS: 0%CPEs: 4EXPL: 0

Adobe ColdFusion 9.0 through 9.0.2, and 10, allows local users to bypass intended shared-hosting sandbox permissions via unspecified vectors. Adobe ColdFusion v9.0 hasta v9.0.2 y v10 permite a usuarios locales evitar permisos de entorno de ejecución seguros en alojamiento compartido a través de vectores no especificados • http://www.adobe.com/support/security/bulletins/apsb12-26.html • CWE-264: Permissions, Privileges, and Access Controls •