Adobe (formerly Macromedia) ColdFusion MX 7.0 exposes the password hash of the Administrator in an API call, which allows local developers to obtain the hash and gain privileges.
References
Link | Resource |
---|---|
http://www.macromedia.com/devnet/security/security_zone/mpsb05-14.html | Patch |
http://www.securityfocus.com/bid/15904 | Patch |
http://securitytracker.com/id?1015371 | Patch Vendor Advisory |
http://secunia.com/advisories/18078 | Patch Vendor Advisory |
http://www.vupen.com/english/advisories/2005/2948 |
Configurations
Information
Published : 2005-12-18 19:47
Updated : 2011-03-07 18:28
NVD link : CVE-2005-4345
Mitre link : CVE-2005-4345
JSON object : View
CWE
Products Affected
macromedia
- coldfusion