The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Coldfusion_server | Allaire | 2.0 (including) | 2.0 (including) |
Coldfusion_server | Allaire | 3.0 (including) | 3.0 (including) |
Coldfusion_server | Allaire | 3.01 (including) | 3.01 (including) |
Coldfusion_server | Allaire | 3.11 (including) | 3.11 (including) |
Coldfusion_server | Allaire | 3.12 (including) | 3.12 (including) |
Coldfusion_server | Allaire | 4.0 (including) | 4.0 (including) |