PT-2013-1384 · Adobe · Coldfusion

Richard Brain

·

Publicado

2013-09-20

·

Atualizado

2017-08-29

·

CVE-2010-5290

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe ColdFusion versions prior to 10
Description The authentication process in Adobe ColdFusion does not require knowledge of the cleartext password if the password hash is known. This makes it easier for attackers to obtain administrative privileges by leveraging read access to the configuration file.
Recommendations For versions prior to 10, update to version 10 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-5290

Produtos afetados

Coldfusion