Allaire ColdFusion Unauthorized File Access Vulnerability
BID:3018
Info
Allaire ColdFusion Unauthorized File Access Vulnerability
| Bugtraq ID: | 3018 |
| Class: | Unknown |
| CVE: |
CVE-2001-1120 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | This vulnerability was submitted to BugTraq in a Macromedia Product Security Bulletin on July 11th, 2001. |
| Vulnerable: |
Allaire ColdFusion Server 4.5.1 SP2 Allaire ColdFusion Server 4.5.1 SP1 Allaire ColdFusion Server 4.5.1 Allaire ColdFusion Server 4.5 Allaire ColdFusion Server 4.0.1 Allaire ColdFusion Server 4.0 Allaire ColdFusion Server 3.1.2 Allaire ColdFusion Server 3.1.1 Allaire ColdFusion Server 3.1 Allaire ColdFusion Server 3.0.1 Allaire ColdFusion Server 3.0 Allaire ColdFusion Server 2.0 |
| Not Vulnerable: |
Allaire ColdFusion Server 5.0 |
Discussion
Allaire ColdFusion Unauthorized File Access Vulnerability
Allaire ColdFusion is a web application server. It supports quick development, publication and management of web content.
A security issue is known to exist with Allaire ColdFusion.
This issue allows attackers to read or delete arbitrary files on the vulnerable host. Disclosure of confidential information or loss of data may occur.
This issue may be exploitable by remote attackers who have access to the host.
At this point, very little is known about the nature of this vulnerability. Updates will be published as more information becomes available.
Allaire ColdFusion is a web application server. It supports quick development, publication and management of web content.
A security issue is known to exist with Allaire ColdFusion.
This issue allows attackers to read or delete arbitrary files on the vulnerable host. Disclosure of confidential information or loss of data may occur.
This issue may be exploitable by remote attackers who have access to the host.
At this point, very little is known about the nature of this vulnerability. Updates will be published as more information becomes available.
Exploit / POC
Allaire ColdFusion Unauthorized File Access Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Allaire ColdFusion Unauthorized File Access Vulnerability
Solution:
It has been reported that if MSVCRT 6.0 runtime files are not installed before applying the patch, server functionality may be affected. Please see the credit section for more details.
The vendor has released patches which address this issue. Please read the FAQ for instructions on how to install the patches:
http://www.allaire.com/handlers/index.cfm?id=21579
Solution:
It has been reported that if MSVCRT 6.0 runtime files are not installed before applying the patch, server functionality may be affected. Please see the credit section for more details.
The vendor has released patches which address this issue. Please read the FAQ for instructions on how to install the patches:
http://www.allaire.com/handlers/index.cfm?id=21579