First published: Wed Feb 14 2001(Updated: )
Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0923 is considered a high severity vulnerability due to its potential to allow remote attackers to read sensitive files and conduct denial of service attacks.
To fix CVE-1999-0923, it is recommended to upgrade to a patched version of ColdFusion Server beyond 4.0.
CVE-1999-0923 can be exploited for file reading, denial of service, and proxying HTTP calls by remote attackers.
CVE-1999-0923 specifically affects ColdFusion Server version 4.0.
Yes, CVE-1999-0923 can be exploited remotely, making it imperative to secure affected servers.