Vulnerabilities > CVE-2005-4342 - Multiple vulnerability in Macromedia Coldfusion 6.0/6.1/7.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager is disabled, which might allow remote attackers to "bypass security controls," aka "JRun Clustered Sandbox Security Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
References
- http://secunia.com/advisories/18078
- http://securitytracker.com/id?1015369
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-12.html
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-14.html
- http://www.securityfocus.com/bid/15904
- http://www.vupen.com/english/advisories/2005/2948