Adobe ColdFusion MX 7 for Linux and Solaris uses insecure permissions for certain scripts and directories, which allows local users to execute arbitrary code or obtain sensitive information via the (1) CFMX7DreamWeaverExtensions.mxp, (2) CFReportBuilderInstaller.exe, (3) .com.zerog.registry.xml, (4) uninstall.lax, (5) license.txt, (6) Readme.htm, (7) .com.zerog.registry.xml, (8) k2adminstop, or (9) k2adminstart files; or (10) certain files in lib/wsconfig/.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2007/1341 | vdb entry |
http://www.adobe.com/support/security/bulletins/apsb07-08.html | patch vendor advisory |
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=510 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/23405 | vdb entry |
http://secunia.com/advisories/24850 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/33571 | vdb entry |
http://www.securitytracker.com/id?1017899 | vdb entry |
http://osvdb.org/34930 | vdb entry |