Vulnerability Name: | CCN-11047 | ||||||
Published: | 2003-01-09 | ||||||
Updated: | 2003-01-09 | ||||||
Summary: | Macromedia ColdFusion MX could allow a remote attacker to escape sandbox restrictions and access restricted files on the system. The <cfinclude> and <cfmodule> tags fail to properly validate file names as arguments. A remote attacker could include a malicious file name containing relative paths, which would allow the attacker to escape sandbox restrictions and access restricted files on the system. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||
CVSS v2 Severity: | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||
Vulnerability Consequences: | Bypass Security | ||||||
References: | Source: CCN Type: Macromedia Product Security Bulletin MPSB03-01 Patch available for ColdFusion MX Enterprise Edition sandbox security issue that allows templates to include arbitrary files Source: CCN Type: BID-6566 Macromedia ColdFusion MX CFInclude And CFModule Tag Sandbox Escaping Vulnerability Source: XF Type: UNKNOWN coldfusion-mx-file-include(11047) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |