10
CVSSv2

CVE-2018-4939

Published: 19/05/2018 Updated: 04/09/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Adobe ColdFusion Update 5 and previous versions versions, ColdFusion 11 Update 13 and previous versions versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe coldfusion 11.0

adobe coldfusion 2016

Github Repositories

post Web ColdFusion RCE – CVE-2018-4939 nickbloorcouk/2018/06/18/another-coldfusion-rce-cve-2018-4939/ Exploitation of Server Side Template Injection with Craft CMS plugin SEOmatic <=313 [CVE-2018-14716] hackerinfo/exploitation-of-server-side-template-injection-with-craft-cms-plguin-seomatic/ SSL/TLS wwwwstspace/ssl-part1-ciphersuite