CyberSec.Space Logo
Back to CVE Browser

CVE-2010-5290

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1820%
EPSS Percentile2.30th
PublishedSep 20, 2013
Last ModifiedApr 29, 2026

Vulnerability Description

The authentication process in Adobe ColdFusion before 10 does not require knowledge of the cleartext password if the password hash is known, which makes it easier for context-dependent attackers to obtain administrative privileges by leveraging read access to the configuration file, a different vulnerability than CVE-2010-2861.

Affected Platforms (CPE)

πŸ“¦
Adobe

Coldfusion

<= 9.0.2
πŸ“¦
Adobe

Coldfusion

= 9.0
πŸ“¦
Adobe

Coldfusion

= 9.0.1

References & Advisories

Related Vulnerabilities