CVE Vulnerabilities

CVE-1999-0455

Published: Dec 25, 1999 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.

Affected Software

NameVendorStart VersionEnd Version
Coldfusion_serverAllaire4.0 (including)4.0 (including)

References