CVE-2018-15960: Input Validation
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known vulnerability vulnerability. Successful exploitation could lead to arbitrary file overwrite.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15960?
CVE-2018-15960 is a vulnerability in Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier, which allows for arbitrary file overwrite.
What is the severity of CVE-2018-15960?
The severity of CVE-2018-15960 is high (7.5).
How can CVE-2018-15960 be exploited?
CVE-2018-15960 can be exploited by leveraging the use of a component with a known vulnerability to perform arbitrary file overwriting.
Which versions of Adobe ColdFusion are affected by CVE-2018-15960?
Adobe ColdFusion versions 11.0 through Update 14 and versions 2016 through Update 6 are affected by CVE-2018-15960.
Where can I find more information about CVE-2018-15960?
You can find more information about CVE-2018-15960 at the following references: [BID 105317](http://www.securityfocus.com/bid/105317), [SecurityTracker ID 1041621](http://www.securitytracker.com/id/1041621), and [Adobe Security Bulletin APSB18-33](https://helpx.adobe.com/security/products/coldfusion/apsb18-33.html).