Adobe ColdFusion Multiple Vulnerabilities (APSB11-04) (credentialed check)

Medium Nessus Plugin ID 55553


A web-based application running on the remote Windows host is affected by multiple vulnerabilities.


The version of Adobe ColdFusion running on the remote Windows host is affected by multiple vulnerabilities :

- Multiple cross-site scripting vulnerabilities exist in the ColdFusion administrator console. (CVE-2011-0580)

- Multiple CRLF injection vulnerabilities in various tags allow adding headers. (CVE-2011-0581)

- An information disclosure vulnerability exists in the ColdFusion administrator console. (CVE-2011-0582)

- A cross-site scripting vulnerability exists with the cfform tag. (CVE-2011-0583)

- A session fixation vulnerability exists for ColdFusion sessions. (CVE-2011-0584)


Apply the relevant hotfixes referenced in the Adobe advisory.

See Also

Plugin Details

Severity: Medium

ID: 55553

File Name: coldfusion_win_apsb11-04.nasl

Version: 1.10

Type: local

Agent: windows

Family: Windows

Published: 2011/07/11

Updated: 2018/11/15

Dependencies: 55514

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:adobe:coldfusion

Required KB Items: SMB/coldfusion/instance

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2011/02/08

Vulnerability Publication Date: 2011/02/08

Reference Information

CVE: CVE-2011-0580, CVE-2011-0581, CVE-2011-0582, CVE-2011-0583, CVE-2011-0584

BID: 46273, 46274, 46277, 46278, 46281

TRA: TRA-2011-01

Secunia: 43264