Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Allaire ColdFusion 未公开 CFML 标记漏洞
Vulnerability Description
ColdFusion是Allaire公司的一个Web应用服务器产品,可运行在多个平台上。 一个恶意的CFML开发者可以使用这些未公开的标记和功能创建Web应用程序在服务器上运行进行很多类型的非授权访问,包括注册表、数据库和其它一些安全存取。 这些标记可以用CFdecrypt utility找到。在3.0版本中主要的危险标记是CFAdmin_Registry_GET和CFAdmin_Registry_SET。4.0版本中主要是CFNEWINTERNALREGISTRY和CFNEWINTERNALADMINS
CVSS Information
N/A
Vulnerability Type
N/A