Macromedia Cold Fusion MX Multiple Vulnerabilities
BID:15904
Info
Macromedia Cold Fusion MX Multiple Vulnerabilities
| Bugtraq ID: | 15904 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 15 2005 12:00AM |
| Updated: | Dec 15 2005 12:00AM |
| Credit: | Russ Michaels discovered the JRun Clustered Sandbox Security Vulnerability. Mike Nicholls discovered the CFMAIL injection Vulnerability. Andy Allan discovered the CFOBJECT Sandbox Security Vulnerability. Fabio Terracini discovered the Administrator Hash |
| Vulnerable: |
Macromedia ColdFusion Server MX 7.0 Macromedia ColdFusion Server MX 6.1 Macromedia ColdFusion Server MX 6.0 Macromedia ColdFusion MX J2EE 6.1 Macromedia ColdFusion MX Enterprise with JRun 6.1 Macromedia ColdFusion MX 7.0 Macromedia ColdFusion MX 6.1 Macromedia ColdFusion MX 6.0 |
| Not Vulnerable: |
Macromedia ColdFusion MX 7.0.1 |
Discussion
Macromedia Cold Fusion MX Multiple Vulnerabilities
Macromedia ColdFusion MX is affect by multiple vulnerabilities.
The following four issues were reported:
- A security vulnerabilty related to the JRun clustered sandbox. This issue affects Macromedia ColdFusion MX 6.0, 6.1. 6.1 with JRun, and 7.0.
- An input validation vulnerability related to the CFMAIL tag. This issue affects Macromedia ColdFusion MX 6.0, 6.1. 6.1 with JRun, and 7.0.
- A security vulnerability related to the CFOBJECT/CreateObject sandbox security setting. This issue affects ColdFusion MX 7.0.
- A security vulnerability that could expose the ColdFusion Administrator password hash to unauthorized parties. This issue affects ColdFusion MX 7.0.
Macromedia ColdFusion MX is affect by multiple vulnerabilities.
The following four issues were reported:
- A security vulnerabilty related to the JRun clustered sandbox. This issue affects Macromedia ColdFusion MX 6.0, 6.1. 6.1 with JRun, and 7.0.
- An input validation vulnerability related to the CFMAIL tag. This issue affects Macromedia ColdFusion MX 6.0, 6.1. 6.1 with JRun, and 7.0.
- A security vulnerability related to the CFOBJECT/CreateObject sandbox security setting. This issue affects ColdFusion MX 7.0.
- A security vulnerability that could expose the ColdFusion Administrator password hash to unauthorized parties. This issue affects ColdFusion MX 7.0.
Exploit / POC
Macromedia Cold Fusion MX Multiple Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Macromedia Cold Fusion MX Multiple Vulnerabilities
Solution:
The vendor has released hot fixes to address these issues on ColdFusion MX 6.x. ColdFusion MX 6.1 Updater is required to install these hot fixes.
This issue has been addressed with the ColdFusion MX 7.0.1 for 7.x releases.
Please see the attached vendor advisories for further information.
Solution:
The vendor has released hot fixes to address these issues on ColdFusion MX 6.x. ColdFusion MX 6.1 Updater is required to install these hot fixes.
This issue has been addressed with the ColdFusion MX 7.0.1 for 7.x releases.
Please see the attached vendor advisories for further information.
References
Macromedia Cold Fusion MX Multiple Vulnerabilities
References:
References: