Adobe ColdFusion Multiple Vulnerabilities (APSB11-04) (credentialed check)

medium Nessus Plugin ID 55553

Synopsis

A web-based application running on the remote Windows host is affected by multiple vulnerabilities.

Description

The version of Adobe ColdFusion running on the remote Windows host is affected by multiple vulnerabilities :

- Multiple cross-site scripting vulnerabilities exist in the ColdFusion administrator console. (CVE-2011-0580)

- Multiple CRLF injection vulnerabilities in various tags allow adding headers. (CVE-2011-0581)

- An information disclosure vulnerability exists in the ColdFusion administrator console. (CVE-2011-0582)

- A cross-site scripting vulnerability exists with the cfform tag. (CVE-2011-0583)

- A session fixation vulnerability exists for ColdFusion sessions. (CVE-2011-0584)

Solution

Apply the relevant hotfixes referenced in the Adobe advisory.

See Also

https://www.tenable.com/security/research/tra-2011-01

https://www.adobe.com/support/security/bulletins/apsb11-04.html

http://kb2.adobe.com/cps/890/cpsid_89094.html

Plugin Details

Severity: Medium

ID: 55553

File Name: coldfusion_win_apsb11-04.nasl

Version: 1.10

Type: local

Agent: windows

Family: Windows

Published: 7/11/2011

Updated: 11/15/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/a:adobe:coldfusion

Required KB Items: SMB/coldfusion/instance

Exploit Ease: No known exploits are available

Patch Publication Date: 2/8/2011

Vulnerability Publication Date: 2/8/2011

Reference Information

CVE: CVE-2011-0580, CVE-2011-0581, CVE-2011-0582, CVE-2011-0583, CVE-2011-0584

BID: 46273, 46274, 46277, 46278, 46281

Secunia: 43264

TRA: TRA-2011-01