vendor:
ColdFusion 8
by:
Pergyz
9,8
CVSS
HIGH
Remote Command Execution (RCE)
78
CWE
Product Name: ColdFusion 8
Affected Version From: 8
Affected Version To: 8
Patch Exists: YES
Related CWE: CVE-2009-2265
CPE: a:adobe:coldfusion:8
Metasploit:
N/A
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=39790, https://www.infosecmatter.com/nessus-plugin-library/?id=39866, https://www.infosecmatter.com/nessus-plugin-library/?id=39806, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/http/coldfusion_fckeditor, https://www.infosecmatter.com/nessus-plugin-library/?id=35819, https://www.infosecmatter.com/nessus-plugin-library/?id=52011, https://www.infosecmatter.com/nessus-plugin-library/?id=35770, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/admin/oracle/osb_execqr2, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/http/dir_webdav_unicode_bypass, https://www.infosecmatter.com/list-of-metasploit-windows-exploits-detailed-spreadsheet/
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows Server 2008 R2 Standard
2021
Adobe ColdFusion 8 – Remote Command Execution (RCE)
A vulnerability in Adobe ColdFusion 8 allows an attacker to execute arbitrary commands on the target system. This is due to the application not properly validating user-supplied input. An attacker can exploit this vulnerability by sending a specially crafted request to the vulnerable application. Successful exploitation of this vulnerability can result in arbitrary code execution on the target system.
Mitigation:
Adobe has released a security update to address this vulnerability. Users are advised to update to the latest version of Adobe ColdFusion 8.