Web Hack List

Collected research

Adobe ColdFusion RCE

Adobe ColdFusion Pre-Auth RCE(s) — ProjectDiscovery Blog

Analyzes ColdFusion deserialization and successive patch bypasses, including an alternative WDDX gadget and inconsistent validation of array type names. The July 2023 writeup distinguishes the initial vulnerability from later bypasses and corrects its earlier patch analysis.

Record

Document
Adobe ColdFusion Pre-Auth RCE(s) — ProjectDiscovery Blog
Researcher
Harsh Jaiswal and Rahul Maini
Published by
ProjectDiscovery
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Harsh Jaiswal and Rahul Maini, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .