Get a Pentest and security assessment of your IT network.

Cyber Security

ColdFusion Zero day vulnerability – Remote File Disclosure of Password Hashes

Most critical ColdFusion vulnerability affects about a tenth of all Coldfusion servers at the present. It chains together multiple exploits, and it provides a 30 second window into the Administrator panel to write out a shell. No other versions can be patched using the LFD->Bypass->RCE exploit. The official Adobe patch can be downloaded from the official patch here. It is only available to fix the vulnerability on ColdFusions 8.0. The vulnerability can only be fixed on the 8.5 version of this version of the software.

Source: https://thehackernews.com/2012/01/coldfusion-zero-day-vulnerability.html

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security