vendor:
ColdFusion 2018
by:
Pankaj Kumar Thakur (Nepal)
7.3
CVSS
HIGH
Unrestricted file upload
434
CWE
Product Name: ColdFusion 2018
Affected Version From: Adobe ColdFusion 2018
Affected Version To: Adobe ColdFusion 2018
Patch Exists: YES
Related CWE: CVE-2016-10258, CVE-2016-1713
CPE: a:adobe:coldfusion:2018
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Adobe ColdFusion 2018
2016
Unrestricted file upload in Adobe ColdFusion 2018
Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code.
Mitigation:
Ensure that the management console is properly secured and that only trusted users have access to it.