ColdFusion Discovery & Enumeration
Overview
HTB Academy Lab Solution
Lab: Protocol Identification
ColdFusion Default Ports
Port
Protocol
Description
Discovery Methods
1. Port Scanning
2. File Extensions
3. Default Directories
4. HTTP Headers
5. Error Messages
Enumeration Techniques
Directory Structure
Version Detection
File Discovery
Key Indicators
HTB Academy Attacking Labs
Lab: ColdFusion User Context
Method 1: Directory Traversal (CVE-2010-2861)
Method 2: Unauthenticated RCE (CVE-2009-2265)
ColdFusion Attack Vectors
1. Directory Traversal (CVE-2010-2861)
2. Unauthenticated RCE (CVE-2009-2265)
3. Common Exploits
Last updated