CVE-2018-15961

CRITICAL KEV NUCLEI LAB

Adobe Coldfusion - Unrestricted File Upload

Title source: rule

Description

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.

Exploits (7)

exploitdb WORKING POC
by Vahagn Vardanyan · textwebappsmultiple
https://www.exploit-db.com/exploits/45979
nomisec WORKING POC 9 stars
by vah13 · remote
https://github.com/vah13/CVE-2018-15961
nomisec WORKING POC 3 stars
by xbufu · remote
https://github.com/xbufu/CVE-2018-15961
nomisec WORKING POC 2 stars
by orangmuda · remote
https://github.com/orangmuda/CVE-2018-15961
nomisec STUB 1 stars
by cved-sources · poc
https://github.com/cved-sources/cve-2018-15961
nomisec WORKING POC
by bu1xuan2 · remote
https://github.com/bu1xuan2/CVE-2018-15961
metasploit WORKING POC EXCELLENT
by Pete Freitag de Foundeo, Vahagn vah_13 Vardanian, Qazeer · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/coldfusion_ckeditor_file_upload.rb

Nuclei Templates (1)

Adobe ColdFusion - Unrestricted File Upload Remote Code Execution
CRITICALby SkyLark-Lab,ImNightmaree
Shodan: http.component:"Adobe ColdFusion" || http.component:"adobe coldfusion" || http.title:"coldfusion administrator login" || cpe:"cpe:2.3:a:adobe:coldfusion"
FOFA: title="coldfusion administrator login" || app="adobe-coldfusion"

Scores

CVSS v3 9.8
EPSS 0.9442
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull eaps-docker-coldfusion.bintray.io/cf/coldfusion:2018.0.0
+3 more repos

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-11-03
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2018-7817
CWE
CWE-434
Status published
Products (3)
adobe/coldfusion 11.0 (15 CPE variants)
adobe/coldfusion 2016 (7 CPE variants)
adobe/coldfusion 2018
Published Sep 25, 2018
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026