S4E just found a high-severity finding from top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

Adobe ColdFusion Unspecified Directory Traversal Vulnerability Scanner

The vulnerability is a variation of a classic directory traversal vulnerability, also referred to as arbitrary file retrieval.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
Detail

Executes a directory traversal attack against a ColdFusion server and tries to grab the password hash for the administrator user. It then uses the salt value (hidden in the web page) to create the SHA1 HMAC hash that the web server needs for authentication as admin. You can pass this value to the ColdFusion server as the admin without cracking the password hash.

Solution Advice

You can either apply Adobe's patch or restrict access to the following directories and file from trusted IP addresses only: /CFIDE/adminapi/ /CFIDE/administrator/ /CFIDE/componentutils/ /CFIDE/wizards/ /CFIDE/install.cfm

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Adobe ColdFusion Unspecified Directory Traversal Vulnerability Scanner | S4E