漏洞描述 Adobe ColdFusion 是美国奥多比(Adobe)公司的一套快速应用程序开发平台。该平台包括集成开发环境和脚本语言。Adobe ColdFusion2016 Update 13及之前版本和ColdFusion 2018 Update7及之前版本中存在安全漏洞。攻击者可利用该漏洞从Coldfusion安装目录中读取任意文件。
相关漏洞推荐 CVE-2023-26360: Unauthenticated File Read Adobe ColdFusion POC 2025-09-01 | Adobe ColdFusion Unauthenticated Arbitrary File Read vulnerability due to deserialization of untrusted data in Adobe ... CVE-2023-29300: Adobe ColdFusion 序列化漏洞 POC 2025-09-01 | Adobe ColdFusion FOFA: app="Adobe-ColdFusion" CVE-2023-38204: Adobe ColdFusion 序列化漏洞 POC 2025-09-01 | Adobe ColdFusion Fofa: app="Adobe-ColdFusion" CVE-2020-10199: Nexus Repository before 3.21.2 allows JavaEL Injection POC 2025-09-01 | Nexus Repository 漏洞触发需要任意账户权限 body="Nexus Repository Manager" app="Nexus-Repository-Manager" CVE-2020-11455: LimeSurvey 4.1.11 - Path Traversal POC 2025-09-01 | LimeSurvey LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/a...