Vulnerabilities > CVE-2007-5905 - Credentials Management vulnerability in Adobe Coldfusion 7.0/8.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Adobe ColdFusion 8 and MX 7 allows remote attackers to hijack sessions via unspecified vectors that trigger establishment of a session to a ColdFusion application in which the (1) CFID or (2) CFTOKEN cookies have empty values, possibly due to a session fixation vulnerability.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Common Weakness Enumeration (CWE)
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 26429 CVE(CAN) ID: CVE-2007-5905 ColdFusion MX是一款高效的网络应用服务器开发环境,具有很高的易用性和开发效率,基于标准的Java技术,可以与XML、Web Services和Microsoft.NET环境相集成。 ColdFusion在处理用户会话时存在漏洞,远程攻击者可能利用此漏洞获取敏感信息。 对于使用ColdFusion编译的应用程序,远程攻击者可以通过CFID或CFTOKEN劫持应用程序的用户会话,然后就可以浏览敏感信息或扮演成为合法用户执行请求。使用J2EE会话管理的用户不受这个漏洞影响。 Adobe ColdFusion MX 7.00 Adobe ColdFusion 8 Adobe ----- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: <a href="http://www.adobe.com/go/kb402805" target="_blank">http://www.adobe.com/go/kb402805</a> |
id | SSV:2425 |
last seen | 2017-11-19 |
modified | 2007-11-15 |
published | 2007-11-15 |
reporter | Root |
title | Adobe ColdFusion CFID/CFTOKEN会话劫持漏洞 |
References
- http://osvdb.org/41478
- http://osvdb.org/41478
- http://secunia.com/advisories/27644
- http://secunia.com/advisories/27644
- http://securitytracker.com/id?1018944
- http://securitytracker.com/id?1018944
- http://www.adobe.com/go/kb402805
- http://www.adobe.com/go/kb402805
- http://www.adobe.com/support/security/bulletins/apsb07-19.html
- http://www.adobe.com/support/security/bulletins/apsb07-19.html
- http://www.securityfocus.com/bid/26429
- http://www.securityfocus.com/bid/26429
- http://www.vupen.com/english/advisories/2007/3859
- http://www.vupen.com/english/advisories/2007/3859
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38446
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38446