The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Coldfusion_server | Allaire | 2.0 | 2.0 |
Coldfusion_server | Allaire | 3.0 | 3.0 |
Coldfusion_server | Allaire | 3.01 | 3.01 |
Coldfusion_server | Allaire | 3.11 | 3.11 |
Coldfusion_server | Allaire | 3.12 | 3.12 |
Coldfusion_server | Allaire | 4.0 | 4.0 |