First published: Wed Jul 11 2001(Updated: )
Unknown vulnerability in ColdFusion Server 2.0 through 4.5.1 SP2 allows remote attackers to overwrite templates with zero byte files via unknown attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =4.5.1-sp2 | |
Adobe ColdFusion | =4.5 | |
Adobe ColdFusion | =2.0 | |
Adobe ColdFusion | =4.0.1 | |
Adobe ColdFusion | =3.0 | |
Adobe ColdFusion | =4.5.1-sp1 | |
Adobe ColdFusion | =4.0 | |
Adobe ColdFusion | =3.1 | |
Adobe ColdFusion | =3.1.1 | |
Adobe ColdFusion | =4.5.1 | |
Adobe ColdFusion | =3.1.2 | |
Adobe ColdFusion | =3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1427 is classified as a medium severity vulnerability.
To fix CVE-2001-1427, upgrade your ColdFusion Server to a version that is not affected by this vulnerability.
If your system is vulnerable to CVE-2001-1427, attackers could overwrite templates with zero byte files, potentially disrupting your applications.
CVE-2001-1427 affects ColdFusion Server versions 2.0 through 4.5.1 SP2.
Yes, there are various attack vectors that could exploit CVE-2001-1427, allowing unauthorized access to file overwrite functionality.