Vulnerabilities > CVE-2013-3336 - Unspecified vulnerability in Adobe Coldfusion
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Unspecified vulnerability in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to read arbitrary files via unknown vectors.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Exploit-Db
description | ColdFusion 9-10 - Credential Disclosure Exploit. CVE-2013-3336. Webapps exploits for multiple platform |
file | exploits/multiple/webapps/25305.py |
id | EDB-ID:25305 |
last seen | 2016-02-03 |
modified | 2013-05-08 |
platform | multiple |
port | |
published | 2013-05-08 |
reporter | HTP |
source | https://www.exploit-db.com/download/25305/ |
title | ColdFusion 9-10 - Credential Disclosure Exploit |
type | webapps |
Metasploit
description | This module uses a directory traversal vulnerability to extract information such as password, rdspassword, and "encrypted" properties. This module has been tested successfully on ColdFusion 9 and ColdFusion 10 (auto-detect). |
id | MSF:AUXILIARY/GATHER/COLDFUSION_PWD_PROPS |
last seen | 2020-06-13 |
modified | 2020-05-12 |
published | 2013-05-13 |
references | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3336 |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/gather/coldfusion_pwd_props.rb |
title | ColdFusion 'password.properties' Hash Extraction |
Nessus
NASL family | CGI abuses |
NASL id | COLDFUSION_APSA13-03.NASL |
description | The version of Adobe ColdFusion running on the remote host is affected by the following vulnerabilities : - A directory traversal vulnerability exists in /administrator/mail/download.cfm. A remote, authenticated attacker can exploit this issue to download arbitrary files. - A local file include vulnerability exists in /adminapi/customtags/l10n.cfm. A remote, unauthenticated attacker can exploit this to execute local cfm files. A remote, unauthenticated attacker can exploit both of these vulnerabilities, resulting in the download of arbitrary files as demonstrated in this plugin report. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 66404 |
published | 2013-05-14 |
reporter | This script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/66404 |
title | Adobe ColdFusion Multiple Vulnerabilities (APSA13-03) |
code |
|
References
- http://www.adobe.com/support/security/advisories/apsa13-03.html
- http://www.adobe.com/support/security/advisories/apsa13-03.html
- http://www.adobe.com/support/security/bulletins/apsb13-13.html
- http://www.adobe.com/support/security/bulletins/apsb13-13.html
- http://www.exploit-db.com/exploits/25305
- http://www.exploit-db.com/exploits/25305