CVE-2010-2861
Adobe ColdFusion Directory Traversal Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
YesDecision
Descriptions
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.
Múltiples vulnerabilidades de salto de directorio en la consola del administrador en ColdFusion de Adobe versión 9.0.1 y anteriores, permiten a los atacantes remotos leer archivos arbitrarios por medio del parámetro locale en los archivos (1) CFIDE/administrador/configuración/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm y (5) enter.cfm en CFIDE/administrador/.
A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-07-27 CVE Reserved
- 2010-08-11 CVE Published
- 2010-08-14 First Exploit
- 2022-03-25 Exploited in Wild
- 2022-04-15 KEV Due Date
- 2024-08-07 CVE Updated
- 2024-09-28 EPSS Updated
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/8137 | Third Party Advisory | |
http://securityreason.com/securityalert/8148 | Third Party Advisory | |
http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861 | X_refsource_misc | |
http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-07 | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/16985 | 2011-03-16 | |
https://www.exploit-db.com/exploits/14641 | 2010-08-14 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.adobe.com/support/security/bulletins/apsb10-18.html | 2013-09-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | <= 9.0.1 Search vendor "Adobe" for product "Coldfusion" and version " <= 9.0.1" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 8.0 Search vendor "Adobe" for product "Coldfusion" and version "8.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 8.0.1 Search vendor "Adobe" for product "Coldfusion" and version "8.0.1" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 9.0 Search vendor "Adobe" for product "Coldfusion" and version "9.0" | - |
Affected
|