Lucene search

K
cvelistMitreCVELIST:CVE-2010-5290
HistorySep 20, 2013 - 4:00 p.m.

CVE-2010-5290

2013-09-2016:00:00
mitre
www.cve.org
1

6.4 Medium

AI Score

Confidence

Low

0.971 High

EPSS

Percentile

99.8%

The authentication process in Adobe ColdFusion before 10 does not require knowledge of the cleartext password if the password hash is known, which makes it easier for context-dependent attackers to obtain administrative privileges by leveraging read access to the configuration file, a different vulnerability than CVE-2010-2861.