First published: Thu Sep 14 2006(Updated: )
Adobe ColdFusion MX 7 and 7.01 allows local users to bypass security restrictions and call components (CFC) within a sandbox from CFML templates that are located outside of the sandbox.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =7.0 | |
Adobe ColdFusion | =7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-4725 is considered moderate due to the potential for local users to bypass security restrictions.
To fix CVE-2006-4725, update Adobe ColdFusion to version 7.0.2 or later where this vulnerability has been addressed.
CVE-2006-4725 affects Adobe ColdFusion MX 7.0 and 7.0.1 on Linux platforms.
CVE-2006-4725 cannot be exploited remotely as it requires local user access to exploit the vulnerability.
Exploiting CVE-2006-4725 allows local users to access and call components within a sandbox, potentially leading to unauthorized actions.