First published: Sat Dec 25 1999(Updated: )
The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Allaire Coldfusion Server | =4.0 | |
Allaire Coldfusion Server | =3.12 | |
Allaire Coldfusion Server | =2.0 | |
Allaire Coldfusion Server | =3.01 | |
Allaire Coldfusion Server | =3.0 | |
Allaire Coldfusion Server | =3.11 | |
=2.0 | ||
=3.0 | ||
=3.01 | ||
=3.11 | ||
=3.12 | ||
=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.