CVE-2006-4725: Medium severity Adobe ColdFusion vulnerability
Published Sep 14, 2006
·Updated
Adobe ColdFusion MX 7 and 7.01 allows local users to bypass security restrictions and call components (CFC) within a sandbox from CFML templates that are located outside of the sandbox.
Affected Software
2 affected components
Adobe ColdFusion=7.0
Adobe ColdFusion=7.0.1
Remediation
Patch Available
Patch Available
Event History
Sep 14, 2006
CVE Published
12:07 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4725?
The severity of CVE-2006-4725 is considered moderate due to the potential for local users to bypass security restrictions.
2
How do I fix CVE-2006-4725?
To fix CVE-2006-4725, update Adobe ColdFusion to version 7.0.2 or later where this vulnerability has been addressed.
3
What versions of Adobe ColdFusion are affected by CVE-2006-4725?
CVE-2006-4725 affects Adobe ColdFusion MX 7.0 and 7.0.1 on Linux platforms.
4
Can CVE-2006-4725 be exploited remotely?
CVE-2006-4725 cannot be exploited remotely as it requires local user access to exploit the vulnerability.
5
What is the impact of exploiting CVE-2006-4725?
Exploiting CVE-2006-4725 allows local users to access and call components within a sandbox, potentially leading to unauthorized actions.