Computer Security
[EN] securityvulns.ru no-pyccku


Adobe Coldfusion multiple security vulnereabilities
Published:15.07.2013
Source:
SecurityVulns ID:13175
Type:remote
Threat Level:
7/10
Description:DoS, code execution.
Affected:ADOBE : ColdFusion 9.0
 ADOBE : ColdFusion 10
CVE:CVE-2013-3350 (Adobe ColdFusion 10 before Update 11 allows remote attackers to call ColdFusion Components (CFC) public methods via WebSockets.)
 CVE-2013-3349 (Unspecified vulnerability in Adobe ColdFusion 9.0 through 9.0.2, when the JRun application server is used, allows remote attackers to cause a denial of service via unknown vectors.)
 CVE-2013-3336 (Unspecified vulnerability in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to read arbitrary files via unknown vectors.)
 CVE-2013-1389 (Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 11, 9.0.1 before Update 10, 9.0.2 before Update 5, and 10 before Update 10 allows remote attackers to execute arbitrary code via unknown vectors.)
Files:Security update: Hotfix available for ColdFusion
 Security update: Hotfixes available for ColdFusion

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod