Macromedia ColdFusion MX Remote Development Service Default Null Password Vulnerability
BID:8110
Info
Macromedia ColdFusion MX Remote Development Service Default Null Password Vulnerability
| Bugtraq ID: | 8110 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2003 12:00AM |
| Updated: | Jul 05 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to rs2112 <[email protected]> and Victim1 <[email protected]>. |
| Vulnerable: |
Macromedia ColdFusion Server MX 6.0 Macromedia ColdFusion Server MX Professional Macromedia ColdFusion Server MX Enterprise Macromedia ColdFusion Server MX Developer |
| Not Vulnerable: | |
Discussion
Macromedia ColdFusion MX Remote Development Service Default Null Password Vulnerability
It has been reported that, by default, the RDS service uses a blank password for authentication.
This could allow an unauthenticated user to access the vulnerable ColdFusion MX server.
It has been reported that, by default, the RDS service uses a blank password for authentication.
This could allow an unauthenticated user to access the vulnerable ColdFusion MX server.
Exploit / POC
Macromedia ColdFusion MX Remote Development Service Default Null Password Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Macromedia ColdFusion MX Remote Development Service Default Null Password Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Macromedia ColdFusion MX Remote Development Service Default Null Password Vulnerability
References:
References:
- Cold Fusion RDS mx remote exploit (cdowns
)