The administrator interface for Adobe ColdFusion 8 and ColdFusion MX7 does not log failed authentication attempts, which makes it easier for remote attackers to conduct brute force attacks without detection.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Coldfusion | Adobe | 7.0 (including) | 7.0 (including) |
Coldfusion | Adobe | 8.0 (including) | 8.0 (including) |