SigmaHQ/rules/web/web_cve_CVE-2010-2861.yaml
2021-08-25 20:14:36 +05:30

28 lines
1.1 KiB
YAML

title: CVE-2010-2861:Adobe ColdFusion 8.0/8.0.1/9.0/9.0.1 LFI
id: e22f6ee2-341a-44b8-a58b-33a0960fa8e0
Author: Subhash Popuri (@pbssubhash)
date: 25/08/2021
status: experimental
description: Multiple directory traversal vulnerabilities in the administrator console
in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files
via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm,
(3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm
in CFIDE/administrator/.
references:
- https://github.com/vulhub/vulhub/tree/master/coldfusion/CVE-2010-2861
- http://www.adobe.com/support/security/bulletins/apsb10-18.html
- https://github.com/projectdiscovery/nuclei-templates
detection:
selection:
c-uri|contains:
- /CFIDE/administrator/enter.cfm?locale=../../../../../../../lib/password.properties%00en
condition: selection
false_positives:
- Scanning from Nuclei
- Penetration Testing Activity
- Unknown
tags:
- attack.initial_access
- attack.t1190
level: critical