logo

Full Disclosure: Adobe ColdFusion Path Traversal for CVE-2010-2861

ID: f6d7ec84-6661-593f-966e-77cdd1d5dadb

STIX ID: report--f6d7ec84-6661-593f-966e-77cdd1d5dadb

Feed Name: TrustedSec blog

Threat Score
50/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

A penetration test identified a pre-auth path traversal/local file disclosure in legacy Adobe ColdFusion (8.x/9.x) via the CFIDE debug endpoint (/CFIDE/debug/cf_debugFr.cfm?userPage=../../etc/hosts), enabling disclosure of local files; the issue was reported to Adobe, which referenced CVE-2010-2861 and indicates newer ColdFusion releases include mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.