PT-2019-5911 · Adobe · Coldfusion
Publicado
2019-06-12
·
Atualizado
2020-09-04
·
CVE-2019-7838
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ColdFusion versions Update 3 and earlier
ColdFusion versions Update 10 and earlier
ColdFusion versions Update 18 and earlier
Description
The issue is related to a file extension blacklist bypass vulnerability, which could allow a remote attacker to execute arbitrary code by exploiting the unlimited upload of dangerous file types. Successful exploitation of this issue may lead to arbitrary code execution.
Recommendations
For ColdFusion versions Update 3 and earlier, update to a version later than Update 3 to resolve the issue.
For ColdFusion versions Update 10 and earlier, update to a version later than Update 10 to resolve the issue.
For ColdFusion versions Update 18 and earlier, update to a version later than Update 18 to resolve the issue.
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Coldfusion