CVE-2010-2861

high

Description

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.

References

http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-07

http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/

http://www.adobe.com/support/security/bulletins/apsb10-18.html

http://securityreason.com/securityalert/8148

http://securityreason.com/securityalert/8137

Details

Source: Mitre, NVD

Published: 2010-08-11

Updated: 2013-09-24

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High