vendor:
ColdFusion MX Server
by:
victim1@angrypacket.com
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: ColdFusion MX Server
Affected Version From: ColdFusion MX Server
Affected Version To: ColdFusion MX Server
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
ColdFusion MX Server RDS Authentication Vulnerability
A vulnerability has been reported for the RDS service that may allow an attacker to obtain unauthorized access to a data residing on a ColdFusion MX server. It is possible for a remote user to configure their web site properties to access files residing on the vulnerable server. Any information obtained in this manner may be used by an attacker to launch further attacks against a vulnerable system.
Mitigation:
Ensure that authentication is properly implemented when communicating with a ColdFusion MX server.