PT-2005-5029 · Adobe · Coldfusion
Published
2005-12-17
·
Updated
2011-03-08
·
CVE-2005-4342
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Adobe ColdFusion versions 6.0 through 7.0
Description
The issue allows remote attackers to bypass security controls because the ColdFusion Sandbox does not throw an exception when the SecurityManager is disabled.
Recommendations
For Adobe ColdFusion versions 6.0 through 7.0, consider enabling the SecurityManager to prevent bypassing of security controls.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coldfusion