Allaire ColdFusion Undocumented CFML Tags Vulnerability

BID:550

Info

Allaire ColdFusion Undocumented CFML Tags Vulnerability

Bugtraq ID: 550
Class: Access Validation Error
CVE:
Remote: No
Local: Yes
Published: Jul 29 1999 12:00AM
Updated: Jul 29 1999 12:00AM
Credit: Allaire Security Bulletin (ASB99-10) released July 29,1999. Additional information emailed to Security Focus by Michael Dinowitz <[email protected]>.
Vulnerable: Allaire ColdFusion Server 4.0.1
Allaire ColdFusion Server 4.0
Allaire ColdFusion Server 3.1.2
Allaire ColdFusion Server 3.1.1
Allaire ColdFusion Server 3.1
Allaire ColdFusion Server 3.0.1
Allaire ColdFusion Server 3.0
Allaire ColdFusion Server 2.0
Not Vulnerable:

Discussion

Allaire ColdFusion Undocumented CFML Tags Vulnerability

A malicious CFML developer could use undocumented tags and functions to create a web application hosted on the local machine that would give the attacker the ability to perform various unauthorized actions, including registry, database, and security access.

This is possible due to certain tags that are available as part of the web administration utility. These tags can be found using the CFdecrypt utility (more information available at http://www.securityfocus.com/vdb/275 ). In 3.0 the most potentially damaging tags are CFAdmin_Registry_GET and CFAdmin_Registry_SET. In 4.0 they are CFNEWINTERNALREGISTRY and CFNEWINTERNALADMINSECURITY. In combination with the cfusion_encrypt() and cfusion_decrypt() functions, these can be used to retrieve and decrypt the admin and studio passwords. With these passwords, they can then use a variety of tools available as part of the web administrtion interface to uploadfiles, retrieve directory listings, etc.

The complete list of functions and tags is:

ColdFusion 4.0x and 3.x Administrative Functions:

CF_SETDATASOURCEUSERNAME()
Sets the default user name for a ColdFusion data source
CF_SETDATASOURCEPASSWORD()
Sets the default password for the ColdFusion data source
CF_ISCOLDFUSIONDATASOURCE()
Verifies a connection to a ColdFusion data source
CF_GETDATASOURCEUSERNAME()
Gets the default user name for a ColdFusion data source
CFUSION_VERIFYMAIL()
Verifies the connection to the default ColdFusion SMTP mail server
CFUSION_GETODBCINI()
Gets ODBC data source information from the Registry
CFUSION_SETODBCINI()
Sets ODBC data source information in the Registry
CFUSION_GETODBCDSN()
Gets the ODBC data source names from the Registry
CFUSION_SETTINGS_REFRESH()
Refreshes some ColdFusion settings not requiring a restart
CFUSION_DBCONNECTIONS_FLUSH()
Disconnects all currently connected ColdFusion datasources
CFUSION_DECRYPT()
3.x only - decrypt function that decrypts a specific string. Deprecated by the
standard Decrypt() function.
CFUSION_ENCRYPT()
3.x only - encrypt function that decrypts a specific string. Deprecated by the
Encrypt() function.

ColdFusion 4.0x Administrative Tags:

CFINTERNALDEBUG
Used for internal ColdFusion debugging by product development and to PCode
templates without executing them (used by the CFML Syntax Checker).
CFNEWINTERNALADMINSECURITY
Used for updates to Advanced Security information.
CFNEWINTERNALREGISTRY
Used for registry updates. This tag is identical to the CFREGISTRY tag but by-passes Basic security.

ColdFusion 3.x Administrative Tags (deprecated in 4.x):

CFADMIN_REGISTRY_SET
Used for registry updates, by-passing Basic security.
CFADMIN_REGISTRY_SET
Used for retrieving registry information, by-passing Basic security.
CFADMIN_REGISTRY_DELETE
Used for registry updates. This tag is identical to the CFREGISTRY tag but by-passes Basic security.

Exploit / POC

Allaire ColdFusion Undocumented CFML Tags Vulnerability

Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].

Solution / Fix

Allaire ColdFusion Undocumented CFML Tags Vulnerability

Solution:
From the Allaire advisory:

Allaire has released a patch that allows administrators of servers hosting multiple applications to disable the undocumented tags and functions using registry settings. To perform server administrative functions, administrators can temporarily re-enable the administrative tags and functions, and disable them again when administrative tasks are complete.

ColdFusion Admin Functions and Tags Patch for 4.01 Professional (Windows NT)
http://www.allaire.com/coldfusion.cfm?web_ID=846

ColdFusion Admin Functions and Tags Patch for 4.01 Enterprise (Windows NT)
http://www.allaire.com/coldfusion.cfm?web_ID=847

ColdFusion Admin Functions and Tags Patch for 4.01 Enterprise (Solaris)
http://www.allaire.com/coldfusion.cfm?web_ID=845

ColdFusion Admin Functions and Tags Patch for 4.01 Enterprise (HP-UX)
http://www.allaire.com/coldfusion.cfm?web_ID=848

ColdFusion Admin Functions and Tags Patch for 3.12 Professional (Windows NT)
http://www.allaire.com/coldfusion.cfm?web_ID=844

For international customers using the French, German or Japanese versions of ColdFusion 4.0, 4.01 of those versions will include this patch. French, German and Japanese versions of ColdFusion 4.01 are available through licensed VARS, resellers and directly from Allaire.

Allaire also recommends that server administrators follow the best practices for securing the ColdFusion Administrator documented in KB Article 10954 Security Best Practice: Securing the ColdFusion Administrator:
http://www.allaire.com/handlers/index.cfm?ID=10954&Method=Full

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report