Macromedia ColdFusion MX Remote Development Service File Disclosure Vulnerability
BID:8109
Info
Macromedia ColdFusion MX Remote Development Service File Disclosure Vulnerability
| Bugtraq ID: | 8109 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2003 12:00AM |
| Updated: | Jul 05 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to rs2112 <[email protected]> and Victim1 <[email protected]>. |
| Vulnerable: |
Macromedia ColdFusion Server MX 6.0 Macromedia ColdFusion Server MX Professional Macromedia ColdFusion Server MX Enterprise Macromedia ColdFusion Server MX Developer |
| Not Vulnerable: | |
Discussion
Macromedia ColdFusion MX Remote Development Service File Disclosure Vulnerability
A vulnerability has been reported for the RDS service that may allow an attacker to obtain unauthorized access to a data residing on a ColdFusion MX server. The vulnerability is due to the way that authentication is done when communicating with a ColdFusion MX server.
It is possible for a remote user to configure their web site properties to access files residing on the vulnerable server.
Any information obtained in this manner may be used by an attacker to launch further attacks against a vulnerable system.
A vulnerability has been reported for the RDS service that may allow an attacker to obtain unauthorized access to a data residing on a ColdFusion MX server. The vulnerability is due to the way that authentication is done when communicating with a ColdFusion MX server.
It is possible for a remote user to configure their web site properties to access files residing on the vulnerable server.
Any information obtained in this manner may be used by an attacker to launch further attacks against a vulnerable system.
Solution / Fix
Macromedia ColdFusion MX Remote Development Service File Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Macromedia ColdFusion MX Remote Development Service File Disclosure Vulnerability
References:
References:
- Cold Fusion RDS mx remote exploit (cdowns
)