Title : Adobe Macromedia ColdFusion Verity Library Privilege Escalation Vulnerabilities VUPEN ID : VUPEN/ADV-2006-4003 CVE ID : CVE-2006-3978
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-10-11
Technical Description
Multiple vulnerabilities have been identified in Adobe Macromedia ColdFusion MX, which could be exploited by malicious users to obtain elevated privileges. These flaws are due to input validation errors in the third party Verity search engine service, which could be exploited by local attackers to execute arbitrary commands with SYSTEM privileges.