10

CVE-2013-3350

Adobe ColdFusion 10 before Update 11 allows remote attackers to call ColdFusion Components (CFC) public methods via WebSockets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Coldfusion Version 10.0
Adobe ≫ Coldfusion Version 10.0 Update update1
Adobe ≫ Coldfusion Version 10.0 Update update2
Adobe ≫ Coldfusion Version 10.0 Update update3
Adobe ≫ Coldfusion Version 10.0 Update update4
Adobe ≫ Coldfusion Version 10.0 Update update8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.56% 0.937
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.adobe.com/support/security/bulletins/apsb13-19.html
Patch
Vendor Advisory
http://www.securitytracker.com/id/1028757
http://stackoverflow.com/questions/17351214/cf10-websocket-p2p-can-invoke-any-public-functions-in-any-cfc-from-javascript-h