The HTML form upload capability in ColdFusion MX 6.1 does not reclaim disk space if an upload is interrupted, which allows remote attackers to cause a denial of service (disk consumption) by repeatedly uploading files and interrupting the uploads before they finish.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Coldfusion | Macromedia | 6.1 (including) | 6.1 (including) |