ColdFusion SandBox Security Bypass Vulnerability
BID:19985
CVE-2006-4725 |Info
ColdFusion SandBox Security Bypass Vulnerability
| Bugtraq ID: | 19985 |
| Class: | Design Error |
| CVE: |
CVE-2006-4725 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 12 2006 12:00AM |
| Updated: | Sep 13 2006 08:57PM |
| Credit: | Stephen Moretti is credited with this vulnerability. |
| Vulnerable: |
Macromedia ColdFusion MX 7.0.1 Macromedia ColdFusion MX 7.0 |
| Not Vulnerable: |
Macromedia ColdFusion MX 7.0.2 |
Discussion
ColdFusion SandBox Security Bypass Vulnerability
ColdFusion is prone to a security-bypass vulnerability because the application fails to ensure that calls to ColdFusion Components (CFCs) are secure within a sandbox.
This issue allows local attackers to use the ColdFusion Markup Language (CFML) templates outside a sandbox to call CFCs within a sandbox.
The exact effects of exploiting this issue are currently unknown. Attackers may possibly exploit this issue to gain access to potentially sensitive information or to execute code that they are not intended to have access to. This may aid them in further attacks. Code execution has not been confirmed.
ColdFusion is prone to a security-bypass vulnerability because the application fails to ensure that calls to ColdFusion Components (CFCs) are secure within a sandbox.
This issue allows local attackers to use the ColdFusion Markup Language (CFML) templates outside a sandbox to call CFCs within a sandbox.
The exact effects of exploiting this issue are currently unknown. Attackers may possibly exploit this issue to gain access to potentially sensitive information or to execute code that they are not intended to have access to. This may aid them in further attacks. Code execution has not been confirmed.
Exploit / POC
ColdFusion SandBox Security Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
ColdFusion SandBox Security Bypass Vulnerability
Solution:
The vendor released security updates to address this issue. Please see the referenced advisory for more information.
Solution:
The vendor released security updates to address this issue. Please see the referenced advisory for more information.
References
ColdFusion SandBox Security Bypass Vulnerability
References:
References: