![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2010-2861 |
Description: | Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.100772 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-2861 http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/ http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-07 http://securityreason.com/securityalert/8137 http://securityreason.com/securityalert/8148 |