← Back

CVE-2010-5290

nvd nist
Published: Sep 20, 2013Modified: Apr 29, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

The authentication process in Adobe ColdFusion before 10 does not require knowledge of the cleartext password if the password hash is known, which makes it easier for context-dependent attackers to obtain administrative privileges by leveraging read access to the configuration file, a different vulnerability than CVE-2010-2861.

Affected (3)

Products: Adobe: Coldfusion
1 product
Coldfusion
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Up to 9.0.2
Version 9.0.1
Version 9.0

Related CWEs

Timeline

No history available yet.