Adobe ColdFusion CFC Method Access Level Security Bypass Vulnerability
BID:28698
Info
Adobe ColdFusion CFC Method Access Level Security Bypass Vulnerability
| Bugtraq ID: | 28698 |
| Class: | Design Error |
| CVE: |
CVE-2008-1656 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 2008 12:00AM |
| Updated: | Apr 16 2008 12:27AM |
| Credit: | Adobe |
| Vulnerable: |
Adobe ColdFusion 8.0.1 Adobe ColdFusion 8.0 |
| Not Vulnerable: | |
Discussion
Adobe ColdFusion CFC Method Access Level Security Bypass Vulnerability
Adobe ColdFusion is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and gain access to CFC methods not intended to be remotely accessible.
This issue affects ColdFusion 8 and 8.0.1.
Adobe ColdFusion is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and gain access to CFC methods not intended to be remotely accessible.
This issue affects ColdFusion 8 and 8.0.1.
Exploit / POC
Adobe ColdFusion CFC Method Access Level Security Bypass Vulnerability
An attacker can use standard tools to exploit this issue.
An attacker can use standard tools to exploit this issue.
Solution / Fix
Adobe ColdFusion CFC Method Access Level Security Bypass Vulnerability
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Adobe ColdFusion 8.0
Adobe ColdFusion 8.0.1
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Adobe ColdFusion 8.0
-
Adobe Patch for ColdFusion Flex2 Remoting Access Level Issue
http://www.adobe.com/go/kb403328
Adobe ColdFusion 8.0.1
-
Adobe Patch for ColdFusion Flex2 Remoting Access Level Issue
http://www.adobe.com/go/kb403328
References
Adobe ColdFusion CFC Method Access Level Security Bypass Vulnerability
References:
References: