Adobe ColdFusion 9.0, 9.0.1, 9.0.2 및 10의 administrator.cfc로 인해 원격 공격자가 기본 빈 암호를 사용하여 RDS 구성요소에 로그인하고 이 세션을 활용해 관리 웹 인터페이스에 접근함으로써 인증을 우회하고 임의 코드를 실행할 가능성이 있으며, 2013년 1월 실제 환경에서 악용되었습니다.
Adobe ColdFusion 9.0, 9.0.1, 9.0.2 및 10의 administrator.cfc로 인해 원격 공격자가 기본 빈 암호를 사용하여 RDS 구성요소에 로그인하고 이 세션을 활용해 관리 웹 인터페이스에 접근함으로써 인증을 우회하고 임의 코드를 실행할 가능성이 있으며, 2013년 1월 실제 환경에서 악용되었습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.