Allaire ColdFusion模板覆盖漏洞

漏洞信息详情

Allaire ColdFusion模板覆盖漏洞

漏洞简介

ColdFusion Server 2.0到4.5.1 SP2版本存在未知漏洞。远程攻击者可以借助未知攻击向量覆盖具有零字节文件的模板。

漏洞公告

The vendor has released patches which address this issue. Please read the FAQ for instructions on how to install the patches:
http://www.allaire.com/handlers/index.cfm?id=21579
Allaire ColdFusion Server 3.1.1

Allaire ColdFusion Server 4.0

Allaire ColdFusion Server 4.0.1

Allaire ColdFusion Server 4.5

Allaire ColdFusion Server 4.5.1

Allaire ColdFusion Server 4.5.1 SP1

参考网址

来源:US-CERT Vulnerability Note: VU#321475
名称: VU#321475
链接:http://www.kb.cert.org/vuls/id/321475

来源: BID
名称: 3023
链接:http://www.securityfocus.com/bid/3023

来源: www.macromedia.com
链接:http://www.macromedia.com/devnet/security/security_zone/mpsb01-07.html

来源: XF
名称: coldfusion-overwrite-template(6840)
链接:http://xforce.iss.net/xforce/xfdb/6840

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享