Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It wouldn't take a zero-day flaw in the Coldfusion stack for a CF application to have an undocumented vulnerability; in fact, it's much more likely that the vulnerability is in the application code than in the stack itself.


A patch has recently been issued (09 APR 2013) by Adobe for the various versions of ColdFusion:

"This hotfix resolves a vulnerability that could be exploited to impersonate an authenticated user (CVE-2013-1387).

"This hotfix resolves a vulnerability that could be exploited by an unauthorized user to gain access to the ColdFusion administrator console (CVE-2013-1388)."

http://www.adobe.com/support/security/bulletins/apsb13-10.ht...


Yep that's bad.


The hacker claims it to be a CF 0-day vulnerability:

> 05:05 < ryan_> manager.linode.com was breached with a coldfusion exploit

...

> 05:33 < Ruchira> ryan||: give us the link to cold fusion vulnerability that you are talking about

> 05:34 < ryan||> Ruchira: 0day

> 05:34 < ryan||> linode staff apparently failed to deduce it themselves and relied on chmodding CFIDE to 000


Depending on who you're talking to, an app-level vulnerability in a Linode management console might be called a "0-day". But it's true that a CF stack flaw is not impossible.


"... CF stack flaw is very possible and almost always likely ..."

There, I fixed it for you. Working with ColdFusion is like this: http://25.media.tumblr.com/38d67be62da60b4d3aa1d0ac22e4e314/...


The problem I have balancing the likelihood of CF stack bugs vs. CF app bugs is that I've had to assess a bunch of CF apps, and they're uniformly coded to mid-1990s best practices. No matter how many bugs have been announced in the CF stack, as a betting man my money would always be on CF app bugs.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: