CVE-2010-2861: Adobe ColdFusion Directory Traversal Vulnerability
A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
Other sources
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2010-2861?
CVE-2010-2861 is classified as a critical vulnerability that can allow remote attackers to read arbitrary files on affected systems.
How do I fix CVE-2010-2861?
To mitigate CVE-2010-2861, upgrade Adobe ColdFusion to version 9.0.2 or later, or apply the appropriate patch provided by Adobe.
Which versions of Adobe ColdFusion are affected by CVE-2010-2861?
CVE-2010-2861 affects Adobe ColdFusion versions 9.0.1 and earlier, as well as version 8.0 and its subsequent minor releases.
What type of vulnerability is CVE-2010-2861?
CVE-2010-2861 is a directory traversal vulnerability in the administrator console of Adobe ColdFusion.
Can CVE-2010-2861 be exploited remotely?
Yes, CVE-2010-2861 allows remote attackers to exploit the vulnerability and access sensitive files.