CVE
- Id
- 47874
- CVE No.
- CVE-2010-5290
- Status
- Candidate
- Description
- The authentication process in Adobe ColdFusion before 10 does not require knowledge of the cleartext password if the password hash is known, which makes it easier for context-dependent attackers to obtain administrative privileges by leveraging read access to the configuration file, a different vulnerability than CVE-2010-2861.
- Phase
- Assigned (20130920)
- Votes
- None (candidate not yet proposed)
- Comments