目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2023-26360 PoC — Adobe ColdFusion 访问控制错误漏洞

来源
关联漏洞
标题: Adobe ColdFusion 访问控制错误漏洞 (CVE-2023-26360)
Description:Adobe ColdFusion是美国奥多比(Adobe)公司的一套快速应用程序开发平台。该平台包括集成开发环境和脚本语言。 Adobe ColdFusion 存在访问控制错误漏洞。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。
Description
CVE-2023-26360 - Adobe Coldfusion 
介绍
# CVE-2023-26360 Vulnerability Scanner

## Overview
**CVE-2023-26360** is a critical remote code execution (RCE) vulnerability in Adobe ColdFusion, affecting specific versions of the software. If exploited, it allows an unauthenticated attacker to execute arbitrary code on a vulnerable server, potentially leading to unauthorized system access, data breaches, and server compromise.

This repository includes a Python-based scanner that checks if a target URL is potentially vulnerable to CVE-2023-26360 by analyzing response headers and specific ColdFusion indicators.

## Affected Versions
Adobe has reported that the following versions of ColdFusion are vulnerable to CVE-2023-26360:
- Adobe ColdFusion 2021 (up to update 6)
- Adobe ColdFusion 2018 (up to update 16)

Adobe has released patches for this vulnerability in later versions. It is highly recommended to apply all available updates if you are using ColdFusion.

## Requirements
The scanner requires:
- **Python 3.7+**
- The following Python packages:
  - `requests`
  - `colorama`

You can install the dependencies with:
```bash
pip install -r requirements.txt
```

## Usage
### Command-Line Arguments
- `url`: The target URL to scan for CVE-2023-26360.


### Running the Scanner
```bash
python cve_2023_26360_scanner.py http://example.com
```

This command checks if the specified URL is potentially vulnerable to CVE-2023-26360

### Sample Output
The script will provide color-coded feedback:
- **Green** for successful connection and ColdFusion version detection.
- **Yellow** for non-vulnerable but detected ColdFusion versions.
- **Red** if the target is likely vulnerable or if errors occur during the scan.

## Google Dork for Identifying Potentially Vulnerable Servers
To help identify publicly accessible ColdFusion instances, you can use the following Google dork:
```plaintext
inurl:"/CFIDE/administrator/index.cfm" intitle:"ColdFusion Administrator"
```
This search string helps locate ColdFusion admin pages, which are commonly exposed and may indicate outdated versions.

## Mitigation
1. **Update Adobe ColdFusion**: Apply the latest security patches provided by Adobe.
2. **Restrict Access**: Limit access to ColdFusion Administrator pages and server endpoints.
3. **Monitor Logs**: Regularly monitor server logs for any unauthorized access attempts.

## Disclaimer
This scanner is for educational and authorized testing purposes only. Unauthorized use of this tool on networks or servers without permission is illegal. Always ensure you have explicit permission from the server owner before performing any tests.

## References
- [Adobe Security Bulletin for CVE-2023-26360](https://helpx.adobe.com/security.html)
- [NIST National Vulnerability Database](https://nvd.nist.gov/vuln/detail/CVE-2023-26360)
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →