CyberSec.Space Logo
返回 CVE 浏览器

CVE-2010-5290

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1820%
EPSS Percentile2.30th
Published2013年9月20日
Last Modified2026年4月29日

Vulnerability Description

The authentication process in Adobe ColdFusion before 10 does not require knowledge of the cleartext password if the password hash is known, which makes it easier for context-dependent attackers to obtain administrative privileges by leveraging read access to the configuration file, a different vulnerability than CVE-2010-2861.

Affected Platforms (CPE)

📦
Adobe

Coldfusion

<= 9.0.2
📦
Adobe

Coldfusion

= 9.0
📦
Adobe

Coldfusion

= 9.0.1

References & Advisories

相关漏洞威胁