Adobe (formerly Macromedia) ColdFusion MX 7.0 exposes the password hash of the Administrator in an API call, which allows local developers to obtain the hash and gain privileges.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Coldfusion |
Macromedia |
7.0 (including) |
7.0 (including) |
References