Press Releases
Wednesday, 18 August 2010 : Important - Millions of Coldfusion sites STILL need to apply patches
Millions of users of Adobe’s ColdFusion programming language are still at risk of losing control of their applications and websites.
Out of the twenty two corporate sites originally surveyed for an exposed ColdFusion admin interface, only two sites have removed the interface with the remaining twenty sites still having the interface exposed. ColdFusion administrators must restrict the admin interface now or their servers will be subject to attacks, also placing their users at risk from uploaded malware.
Penetration testing company ProCheckUp has now released full details of this advisory http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-07 as promised, so that readers can now see for themselves how trivial it is to fully compromise one of the millions of exposed ColdFusion servers.
The advisory demonstrates how penetration testing company ProCheckUp were able to access every file including username and passwords from a server running ColdFusion. This was completed through a directory traversal and file retrieval flaw found within ColdFusion administrator. A standard web browser was used to carry out the attack; knowledge of the admin password is not needed.
A competent attacker would be able to steal files from the server and gain access to secure areas as well and eventually modify content or shut down the website or application.
Richard Brain of ProCheckUp commented “This is a trivial attack which can be performed easily by a competent engineer; ProCheckUp thanks Adobe for consciously working with us to produce a patch which fixes the traversal attack. By performing a simple Google search for inurl:index.cfm, it was found that over 80 millions indexes from sites using ColdFusion.
‘Hackers’ over the weekend reversed engineered and published the exploit code, by studying this exploit code industry experts have also commented about the critical impact exploiting this vulnerability has. See:- Adobe ColdFusion's Directory Traversal Disaster http://h30507.www3.hp.com/t5/Following-the-White-Rabbit-A/Adobe-ColdFusion-s-Directory-Traversal-Disaster/ba-p/81964
The full details of the vulnerability can be found on http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-07
