CVE-2010-5290
Last modified
CVE-2010-5290 is a vulnerability of currently unknown severity. The authentication process in Adobe ColdFusion before 10 does not require knowledge of the cleartext password if the password hash is known, which makes it easier for context-dependent attackers to obtain administrative privileges by leveraging read access to the configuration file, a different vulnerability than CVE-2010-2861.. EPSS estimates a 5.53% chance of exploitation in the next 30 days.
Description
The authentication process in Adobe ColdFusion before 10 does not require knowledge of the cleartext password if the password hash is known, which makes it easier for context-dependent attackers to obtain administrative privileges by leveraging read access to the configuration file, a different vulnerability than CVE-2010-2861.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Coldfusion | <= 9.0.2 |
| Adobe | Coldfusion | 9.0 |
| Adobe | Coldfusion | 9.0.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-5290?
How severe is CVE-2010-5290?
How do I fix CVE-2010-5290?
Are you affected by CVE-2010-5290?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
