CVE-2018-15961
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.
- Affected products
- Coldfusion
- Adobe Coldfusion
- = 11.0, 2016, 2018
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 100.0% (100th percentile)
- Weakness
- CWE-434
- NVD status
- Analyzed
- Published
- 2018-09-25
CVE-2018-15961 at NVD
15 known exploits for CVE-2018-15961
Proof-of-concept code and exploit modules indexed by Sploitus
cve-2018-15961
CVE-2018-15961
CVE-2018-15961
CVE-2018-15961
CVE-2018-15961
Exploit for Unrestricted Upload of File with Dangerous Type in Adobe Coldfusion
Exploit for Unrestricted Upload of File with Dangerous Type in Adobe Coldfusion
Adobe Coldfusion 11 CKEditor Arbitrary File Upload Exploit
Adobe Coldfusion 11 CKEditor Arbitrary File Upload
Adobe ColdFusion File Upload
Adobe ColdFusion 2018 - Arbitrary File Upload Vulnerability
Adobe ColdFusion 2018 Shell Upload
Adobe ColdFusion 2018 - Arbitrary File Upload
Adobe ColdFusion 2018 - Arbitrary File Upload
Adobe ColdFusion CKEditor unrestricted file upload