CVE Vulnerabilities

CVE-1999-0455

Published: Dec 25, 1999 | Modified: Sep 09, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.

Affected Software

Name Vendor Start Version End Version
Coldfusion_server Allaire 4.0 (including) 4.0 (including)

References