Schweregrad: : Alto
  Identificador(es) CVE: : CVE-2010-2861
  Data do informe: 21 julho 2015

  Descrição

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.

  Exposição das informações

Apply associated Trend Micro DPI Rules.

  Solução

  Trend Micro Deep Security DPI Rule Number: 1004363
  Trend Micro Deep Security DPI Rule Name: 1004363 - Adobe ColdFusion Directory Traversal Vulnerability

  Software infectado e versão:

  • Adobe Coldfusion 8.0
  • Adobe Coldfusion 8.0.1
  • Adobe Coldfusion 9.0
  • Adobe Coldfusion 9.0.1