ColdFusion AdminAPI Authentication Bypass Vulnerability
BID:19426
CVE-2006-3979 |Info
ColdFusion AdminAPI Authentication Bypass Vulnerability
| Bugtraq ID: | 19426 |
| Class: | Unknown |
| CVE: |
CVE-2006-3979 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2006 12:00AM |
| Updated: | Aug 09 2006 08:05PM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
Macromedia ColdFusion MX 7.0.2 Macromedia ColdFusion MX 7.0.1 Macromedia ColdFusion MX 7.0 |
| Not Vulnerable: | |
Discussion
ColdFusion AdminAPI Authentication Bypass Vulnerability
ColdFusion is prone to an authentication-bypass vulnerability. This issue is due to the application's failure to ensure that remote users have the proper credentials before allowing access to administrative functionality.
This issue allows remote attackers to bypass authentication tests and obtain access to all administrative functionality through the application programming interface (API). This may aid them in further attacks.
ColdFusion is prone to an authentication-bypass vulnerability. This issue is due to the application's failure to ensure that remote users have the proper credentials before allowing access to administrative functionality.
This issue allows remote attackers to bypass authentication tests and obtain access to all administrative functionality through the application programming interface (API). This may aid them in further attacks.
Exploit / POC
ColdFusion AdminAPI Authentication Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
ColdFusion AdminAPI Authentication Bypass Vulnerability
Solution:
The vendor released security updates to address this issue. Please see the referenced advisories for further information.
Solution:
The vendor released security updates to address this issue. Please see the referenced advisories for further information.
References
ColdFusion AdminAPI Authentication Bypass Vulnerability
References:
References:
- Adobe ColdFusion Homepage (Adobe)
- ColdFusion AdminAPI Authentication Issue (Adobe)