ColdFusion 0dayÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-03-04Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-7816£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
ÊÜÓ°ÏìÈí¼þÒÔ¼°°æ±¾£º
ColdFusion 2018
ColdFusion 2016
ColdFusion 11
Îó²î¸ÅÊö
ColdFusionÊÇÒ»¸ö¶¯Ì¬WebЧÀÍÆ÷£¬£¬£¬£¬£¬ÆäCFML£¨ColdFusion Markup Language£©ÊÇÒ»ÖÖ³ÌÐòÉè¼ÆÓïÑÔ£¬£¬£¬£¬£¬ÀàËÆÏÖÔÚµÄJavaServer PageÀïµÄJSTL£¨JSP Standard Tag Lib£©£¬£¬£¬£¬£¬´Ó1995Äê×îÏÈ¿ª·¢£¬£¬£¬£¬£¬ÆäÉè¼ÆÍ·ÄÔ±»Ò»Ð©ÈËÒÔΪºÜÊÇÏȽø£¬£¬£¬£¬£¬±»Ò»Ð©ÓïÑÔËù½è¼ø¡£¡£¡£¡£¡£¡£
AdobeÐû²¼½ôÆÈ¸üУ¬£¬£¬£¬£¬ÐÞ¸´ÁËColdFusion WebÓ¦ÓóÌÐò¿ª·¢Æ½Ì¨µÄÒªº¦Îó²î¡£¡£¡£¡£¡£¡£¸Ã¹ýʧ¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐУ¬£¬£¬£¬£¬²¢ÒÑÔÚÒ°ÍⱻʹÓᣡ£¡£¡£¡£¡£
Çå¾²ÎÊÌâÔÊÐí¹¥»÷ÕßÈÆ¹ýÉÏ´«ÎļþµÄÏÞÖÆ¡£¡£¡£¡£¡£¡£ÒªÊ¹ÓÃËü£¬£¬£¬£¬£¬¹¥»÷Õß±ØÐèÄܹ»½«¿ÉÖ´ÐдúÂëÉÏÔØµ½WebЧÀÍÆ÷ÉϵÄÎļþĿ¼¡£¡£¡£¡£¡£¡£
AdobeÔÚÆäÇ徲ͨ¸æÖгƣ¬£¬£¬£¬£¬¸Ã´úÂë¿ÉÒÔͨ¹ýHTTPÇëÇóÖ´ÐС£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚAdobeÒÑÐû²¼²¹¶¡£¬£¬£¬£¬£¬ÇëÓû§¾¡¿ì¾ÙÐа汾¸üУºhttps://helpx.adobe.com/security/products/coldfusion/apsb19-14.html¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://helpx.adobe.com/security/products/coldfusion/apsb19-14.html