Vulnerability Name: | CVE-2006-3978 (CCN-29475) | ||||||||
Assigned: | 2006-10-10 | ||||||||
Published: | 2006-10-10 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | Unspecified vulnerability in a Verity third party library, as used on Adobe ColdFusion MX 7 through MX 7.0.2 and possibly other products, allows local users to execute arbitrary code via unknown attack vectors. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P) 3.4 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-3978 Source: CCN Type: SA22312 Adobe ColdFusion Verity Library Privilege Escalation Vulnerability Source: SECUNIA Type: UNKNOWN 22312 Source: CCN Type: SECTRACK ID: 1017040 Macromedia ColdFusion 3rd Party Bug Lets Local Users Gain Local System Privileges Source: SECTRACK Type: UNKNOWN 1017040 Source: CCN Type: Adobe Macromedia Products Web site ColdFusion MX 7 Source: CCN Type: Adobe Product Security Bulletin APSB06-17 Patch available for ColdFusion MX 7 local privilege escalation Source: CONFIRM Type: Patch http://www.adobe.com/support/security/bulletins/apsb06-17.html Source: CCN Type: OSVDB ID: 29624 ColdFusion MX Search Service Verity Library rcadmin.exe Multiple Command Local Overflow Source: BID Type: UNKNOWN 20431 Source: CCN Type: BID-20431 Adobe ColdFusion MX Verity Library Local Privilege Escalation Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-4003 Source: XF Type: UNKNOWN coldfusion-library-privilege-escalation(29475) Source: XF Type: UNKNOWN coldfusion-library-gain-privileges(29475) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |