PT-2001-1090 · Adobe · Coldfusion Server
Published
2001-03-12
·
Updated
2008-09-05
·
CVE-1999-0923
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ColdFusion Server version 4.0
Description
The issue allows remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls through sample runnable code snippets.
Recommendations
For ColdFusion Server version 4.0, remove or restrict access to the sample runnable code snippets to prevent exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coldfusion Server