Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.
The product allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product’s environment.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Coldfusion | Adobe | 11.0 (including) | 11.0 (including) |
Coldfusion | Adobe | 11.0-update1 (including) | 11.0-update1 (including) |
Coldfusion | Adobe | 11.0-update10 (including) | 11.0-update10 (including) |
Coldfusion | Adobe | 11.0-update11 (including) | 11.0-update11 (including) |
Coldfusion | Adobe | 11.0-update12 (including) | 11.0-update12 (including) |
Coldfusion | Adobe | 11.0-update13 (including) | 11.0-update13 (including) |
Coldfusion | Adobe | 11.0-update14 (including) | 11.0-update14 (including) |
Coldfusion | Adobe | 11.0-update2 (including) | 11.0-update2 (including) |
Coldfusion | Adobe | 11.0-update3 (including) | 11.0-update3 (including) |
Coldfusion | Adobe | 11.0-update4 (including) | 11.0-update4 (including) |
Coldfusion | Adobe | 11.0-update5 (including) | 11.0-update5 (including) |
Coldfusion | Adobe | 11.0-update6 (including) | 11.0-update6 (including) |
Coldfusion | Adobe | 11.0-update7 (including) | 11.0-update7 (including) |
Coldfusion | Adobe | 11.0-update8 (including) | 11.0-update8 (including) |
Coldfusion | Adobe | 11.0-update9 (including) | 11.0-update9 (including) |
Coldfusion | Adobe | 2016 (including) | 2016 (including) |
Coldfusion | Adobe | 2016-update1 (including) | 2016-update1 (including) |
Coldfusion | Adobe | 2016-update2 (including) | 2016-update2 (including) |
Coldfusion | Adobe | 2016-update3 (including) | 2016-update3 (including) |
Coldfusion | Adobe | 2016-update4 (including) | 2016-update4 (including) |
Coldfusion | Adobe | 2016-update5 (including) | 2016-update5 (including) |
Coldfusion | Adobe | 2016-update6 (including) | 2016-update6 (including) |
Coldfusion | Adobe | 2018 (including) | 2018 (including) |