CVE-2007-1874

CVE-2007-1874

CVE-2007-1874 · HIGH Severity

AV:L/AC:L/AU:N/C:C/I:C/A:C

Adobe ColdFusion MX 7 for Linux and Solaris uses insecure permissions for certain scripts and directories, which allows local users to execute arbitrary code or obtain sensitive information via the (1) CFMX7DreamWeaverExtensions.mxp, (2) CFReportBuilderInstaller.exe, (3) .com.zerog.registry.xml, (4) uninstall.lax, (5) license.txt, (6) Readme.htm, (7) .com.zerog.registry.xml, (8) k2adminstop, or (9) k2adminstart files; or (10) certain files in lib/wsconfig/.

Learn more about our Cis Benchmark Audit For Distribution Independent Linux.