- An important vulnerability (CVE-2010-0185) has been identified in ColdFusion 9.0, which could allow access to collections created by the Solr Service to be accessed from any external machine using a specific URL. By accessing the ColdFusion Solr collections, a user could search and index the information contained in the collections. Adobe has provided a solution to the reported vulnerability. It is recommended that users update their product installations using the instructions provided below.
- Disable external access to the Solr collections.
- WordPress Plugin Forms:3rd-Party Inject Results Cross-Site Scripting (0.2)
- WordPress Plugin wp-FileManager Arbitrary File Disclosure (1.3.0)
- WordPress Plugin Social Share Button Cross-Site Scripting (2.1)
- WordPress 2.0.2 Username Remote PHP Code Injection Vulnerability (0.6.2 - 2.0.2)
- WordPress Plugin Jigoshop Information Disclosure (1.17.9)