PT-2005-5030 · Adobe · Coldfusion

Published

2005-12-17

·

Updated

2011-03-08

·

CVE-2005-4343

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Adobe ColdFusion versions 6.0 through 7.0
Description The issue allows remote attackers to attach arbitrary files and send mail via a crafted Subject field. This is due to improper handling by the CFMAIL tag in applications that use ColdFusion.
Recommendations For versions 6.0 through 7.0, update the CFMAIL tag handling to properly validate and sanitize the Subject field to prevent attachment of arbitrary files.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4343

Affected Products

Coldfusion