PT-2005-5030 · Adobe · Coldfusion
Publicado
2005-12-17
·
Atualizado
2011-03-08
·
CVE-2005-4343
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe ColdFusion versions 6.0 through 7.0
Description
The issue allows remote attackers to attach arbitrary files and send mail via a crafted Subject field. This is due to improper handling by the CFMAIL tag in applications that use ColdFusion.
Recommendations
For versions 6.0 through 7.0, update the CFMAIL tag handling to properly validate and sanitize the Subject field to prevent attachment of arbitrary files.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Coldfusion