10
CVSSv2

CVE-2010-5290

Published: 20/09/2013 Updated: 29/08/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The authentication process in Adobe ColdFusion prior to 10 does not require knowledge of the cleartext password if the password hash is known, which makes it easier for context-dependent malicious users to obtain administrative privileges by leveraging read access to the configuration file, a different vulnerability than CVE-2010-2861.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe coldfusion 9.0

adobe coldfusion

adobe coldfusion 9.0.1