Junglewise Threat Intelligence

CVE-2010-2861: Adobe ColdFusion Directory Traversal Vulnerability

CVE-2010-2861 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Multiple directory traversal vulnerabilities in the Adobe ColdFusion administrator console allow remote attackers to read arbitrary files. The flaw exists in the locale parameter across several components, including settings/mappings.cfm and enter.cfm.

Affected products

  • Adobe ColdFusion 9.0.1 and earlier

Timeline

  • 2010-08-11: disclosed: NVD Published Date
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-15: other: CISA KEV required action due date

Related threats