The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Coldfusion_server | Allaire | 4.0 (including) | 4.0 (including) |