PT-2019-5911 · Adobe · Coldfusion

Publicado

2019-06-12

·

Atualizado

2020-09-04

·

CVE-2019-7838

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ColdFusion versions Update 3 and earlier ColdFusion versions Update 10 and earlier ColdFusion versions Update 18 and earlier
Description The issue is related to a file extension blacklist bypass vulnerability, which could allow a remote attacker to execute arbitrary code by exploiting the unlimited upload of dangerous file types. Successful exploitation of this issue may lead to arbitrary code execution.
Recommendations For ColdFusion versions Update 3 and earlier, update to a version later than Update 3 to resolve the issue. For ColdFusion versions Update 10 and earlier, update to a version later than Update 10 to resolve the issue. For ColdFusion versions Update 18 and earlier, update to a version later than Update 18 to resolve the issue.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2021-03785
CVE-2019-7838

Produtos afetados

Coldfusion