Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/ | exploit |
http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-07 | broken link |
http://www.adobe.com/support/security/bulletins/apsb10-18.html | not applicable vendor advisory |
http://securityreason.com/securityalert/8137 | third party advisory broken link |
http://securityreason.com/securityalert/8148 | third party advisory broken link |