Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 mishandles wildcards in name fields of X.509 certificates, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Adobe ColdFusion 安全漏洞
Vulnerability Description
Adobe ColdFusion是美国奥多比(Adobe)公司的一款动态Web服务器产品,其运行的CFML(ColdFusion Markup Language)是针对Web应用的一种程序设计语言。 Adobe ColdFusion中存在安全漏洞,该漏洞源于程序没有正确处理X.509证书的名称字段中的通配符。攻击者可借助特制的证书利用该漏洞实施中间人攻击,欺骗服务器。以下版本受到影响:Adobe ColdFusion 2016.0.0版本,Update 7及之前版本,Update 18及之前版本。
CVSS Information
N/A
Vulnerability Type
N/A