CVE-2005-4345
7.2
CVSS SCORE
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
Description
Adobe (formerly Macromedia) ColdFusion MX 7.0 exposes the password hash of the Administrator in an API call, which allows local developers to obtain the hash and gain privileges.
CVSS Vector Details
Attack Vector
Local
Attack Complexity
Low
Confidentiality
C
Integrity
C
Availability
C
Affected Software Configurations
- a macromedia coldfusion 7.0 * * * * * * *
Weaknesses (CWE)
- NVD-CWE-Other
References & External Links
- http://secunia.com/advisories/18078
- http://securitytracker.com/id?1015371
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-14.html
- http://www.securityfocus.com/bid/15904
- http://www.vupen.com/english/advisories/2005/2948
- http://secunia.com/advisories/18078
- http://securitytracker.com/id?1015371
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-14.html
- http://www.securityfocus.com/bid/15904
- http://www.vupen.com/english/advisories/2005/2948