ColdFusion 0dayÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-03-04

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-7816£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


ÊÜÓ°ÏìÈí¼þÒÔ¼°°æ±¾£º 

ColdFusion 2018

ColdFusion 2016

ColdFusion 11


Îó²î¸ÅÊö


ColdFusionÊÇÒ»¸ö¶¯Ì¬WebЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬£¬ÆäCFML£¨ColdFusion Markup Language£©ÊÇÒ»ÖÖ³ÌÐòÉè¼ÆÓïÑÔ£¬£¬£¬£¬£¬£¬£¬£¬ÀàËÆÏÖÔÚµÄJavaServer PageÀïµÄJSTL£¨JSP Standard Tag Lib£©£¬£¬£¬£¬£¬£¬£¬£¬´Ó1995Äê×îÏÈ¿ª·¢£¬£¬£¬£¬£¬£¬£¬£¬ÆäÉè¼ÆÍ·ÄÔ±»Ò»Ð©ÈËÒÔΪºÜÊÇÏȽø£¬£¬£¬£¬£¬£¬£¬£¬±»Ò»Ð©ÓïÑÔËù½è¼ø ¡£¡£¡£


AdobeÐû²¼½ôÆÈ¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËColdFusion WebÓ¦ÓóÌÐò¿ª·¢Æ½Ì¨µÄÒªº¦Îó²î ¡£¡£¡£¸Ã¹ýʧ¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬£¬£¬²¢ÒÑÔÚÒ°ÍⱻʹÓà ¡£¡£¡£


Çå¾²ÎÊÌâÔÊÐí¹¥»÷ÕßÈÆ¹ýÉÏ´«ÎļþµÄÏÞÖÆ ¡£¡£¡£ÒªÊ¹ÓÃËü£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß±ØÐèÄܹ»½«¿ÉÖ´ÐдúÂëÉÏÔØµ½WebЧÀÍÆ÷ÉϵÄÎļþĿ¼ ¡£¡£¡£

AdobeÔÚÆäÇ徲ͨ¸æÖгÆ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã´úÂë¿ÉÒÔͨ¹ýHTTPÇëÇóÖ´ÐÐ ¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚAdobeÒÑÐû²¼²¹¶¡£¬£¬£¬£¬£¬£¬£¬£¬ÇëÓû§¾¡¿ì¾ÙÐа汾¸üУºhttps://helpx.adobe.com/security/products/coldfusion/apsb19-14.html ¡£¡£¡£


²Î¿¼Á´½Ó


https://helpx.adobe.com/security/products/coldfusion/apsb19-14.html