Adobe ColdFusion Multiple Vulnerabilities
Last Update Date:
16 Jun 2011 15:48
Release Date:
16 Jun 2011
6427
Views
RISK: High Risk
TYPE: Servers - Internet App Servers
Multiple vulnerabilities have been identified in Adobe ColdFusion, which can be exploited by malicious people to conduct cross-site request forgery attacks, cause a DoS (Denial of Service), and compromise a vulnerable system.
- The administrative interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to e.g. add a user with administrative privileges by tricking the logged in administrator into visiting a malicious web site.
- An unspecified error can be exploited to cause a DoS.
- Some vulnerabilities are caused due to vulnerabilities in the bundled version of Adobe BlazeDS.
Impact
- Denial of Service
- Remote Code Execution
- Spoofing
System / Technologies affected
- Adobe ColdFusion versions 9.0.1, 9.0, 8.0.1, and 8.0 for Windows, Macintosh, and UNIX.
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Vulnerability Identifier
Source
Related Link
Share with