CVE-2010-2861 comprises multiple directory traversal vulnerabilities in the administrator console of Adobe ColdFusion 9.0.1 and earlier. Manipulation of the locale parameter in administrator pages for mappings, logging settings, data sources, J2EE archive editing, and administrator entry allows remote attackers to read arbitrary files. Exploitation can expose sensitive server files, including credential-related configuration data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This is a deliberately vulnerable CTF/training lab with valid, documentation-only exploitation requests for CVE-2010-2861, rather than an automated exploit tool. The locale parameter of the administrator login page is used in a filesystem path; traversal combined with %00 can disclose arbitrary readable files, including administrator password material. No code execution or credential cracking is implemented, and the contents were not executed or dynamically verified. The 33 files comprise a central Isoloom specification, generated deployment infrastructure, checks, upstream documentation, and an image build recipe. app/ vendors the Vulhub walkthrough in English and Chinese plus its original Compose file. base/coldfusion/8.0.1/ contains a Dockerfile, silent-install settings, and a Bash downloader for ColdFusion 8.0.1 on Ubuntu 14.04. .isoloom/ supplies Docker Compose, Kubernetes manifests and check Jobs, a Vagrant wrapper, Proxmox Terraform, and Terraform deployments for AWS, Azure, DigitalOcean, GCP, Linode, and OCI. GitHub workflows validate the generated files, start and test the lab, and register approved labs using secret-provided publishing endpoints. .ctf/metadata.json describes a file-reading flag challenge, but no flag file or flag-placement implementation appears in the supplied files. The 15 code/build files counted are seven Terraform files, six shell scripts, one Ruby Vagrantfile, and one Dockerfile; YAML deployment and workflow configurations are listed as an additional detected language but excluded from that code-file count. checks/locale.sh only requests locale=en and checks for ColdFusion branding. Generated checks validate HTTP readiness and blocked outbound connectivity, not the vulnerability itself. The README also mentions four other administrator endpoints as affected, but no supplied code requests them. Isoloom is deployment orchestration, not an identified exploit framework. Docker defaults to loopback publishing and removes the vulnerable container's default route. Cloud deployments expose SSH and TCP 8500 to a supplied allowed_cidr; Kubernetes publishes TCP 8500 through a LoadBalancer and permits ingress from any IPv4 source, while egress restrictions depend on NetworkPolicy enforcement. The original app Compose file has no comparable isolation controls. The runtime is configured as root with administrator password admin. Cleanup commands in CI and provisioning are contextual housekeeping, not evidence of a fake exploit. The English password-file example contains an apparent formatting error; the Chinese example provides the corresponding path without the stray space. No original analyzed repository URL, analyzed git ref, archive path, or archive byte size was supplied. Empty repository URL/ref and size 0 are unknown-value placeholders. UPSTREAM.md identifies the vendored source as github.com/vulhub/vulhub at commit 8fd63916f7a8711e2e01dda0d27237e4d6175d38, which is not necessarily the analyzed repository's ref.
This repository contains a Python 3 port of a classic exploit for CVE-2010-2861, a directory traversal vulnerability in Adobe ColdFusion. The main file, 14641-v2.py, is a standalone exploit script that connects to a specified host and port, and attempts to read arbitrary files from the server by sending crafted POST requests to several known ColdFusion administrative endpoints under /CFIDE/. The exploit leverages a directory traversal payload in the 'locale' POST parameter to access files such as password.properties. The script prints out the <title> of the returned page or the HTTP headers if no title is found, providing feedback on the success of the attack. The repository is simple, containing only the exploit script and a brief README. No detection or fake code is present; this is a functional proof-of-concept exploit for educational purposes.
This repository contains a single Metasploit auxiliary scanner module targeting a directory traversal vulnerability (CVE-2010-2861) in Adobe ColdFusion (versions MX6, MX7, MX8). The module attempts to exploit the 'locale' parameter in several ColdFusion administrative endpoints (e.g., /CFIDE/administrator/enter.cfm) to traverse directories and retrieve sensitive files such as password.properties, which may contain administrative credentials. The module first fingerprints the target to determine the ColdFusion version and operating system, then constructs the appropriate traversal payload to retrieve the file. The exploit is operational and can be used to confirm the presence of the vulnerability and extract sensitive files from unpatched ColdFusion servers. The code is written in Ruby and is designed to be run within the Metasploit Framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A directory traversal vulnerability in Adobe ColdFusion exploited to retrieve password.properties from an internet-facing ColdFusion 9 server. It formed part of the initial compromise leading to Cring ransomware deployment. The article states that the end-of-life ColdFusion installation could no longer be patched and advises against exposing outdated critical systems to the internet.
A directory traversal vulnerability in Adobe ColdFusion exploited to retrieve password.properties from an internet-facing ColdFusion 9 server. It formed part of the initial compromise leading to Cring ransomware deployment. The article states that the end-of-life ColdFusion installation could no longer be patched and advises against exposing outdated critical systems to the internet.
An Adobe ColdFusion vulnerability that the content says was abused by operators behind Cring ransomware for initial access.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.