危険度:
  CVE識別番号: CVE-2010-2861
  情報公開日: 7 21, 2015

  概要

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.

  トレンドマイクロの対策

Apply associated Trend Micro DPI Rules.

  対応方法

  Trend Micro Deep Security DPI Rule Number: 1004363
  Trend Micro Deep Security DPI Rule Name: 1004363 - Adobe ColdFusion Directory Traversal Vulnerability

  影響を受けるソフトウェア

  • Adobe Coldfusion 8.0
  • Adobe Coldfusion 8.0.1
  • Adobe Coldfusion 9.0
  • Adobe Coldfusion 9.0.1