PT-2001-1739 · Adobe · Coldfusion Server

Publicado

2001-10-12

·

Atualizado

2008-09-05

·

CVE-2001-0535

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: ColdFusion Server versions 4.x
Description: The issue allows remote attackers to upload, read, or execute files by spoofing the HTTP Host (CGI.Host) variable in example scripts, specifically in the Web Publish and Email example scripts. This is due to improper restriction of access from outside the local host's domain.
Recommendations: For ColdFusion Server version 4.x, restrict access to the Web Publish and Email example scripts to prevent remote attackers from spoofing the HTTP Host (CGI.Host) variable. As a temporary workaround, consider disabling the Web Publish and Email example scripts until a proper fix is applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0535

Produtos afetados

Coldfusion Server