PT-2005-5030 · Adobe · Coldfusion
Published
2005-12-17
·
Updated
2011-03-08
·
CVE-2005-4343
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe ColdFusion versions 6.0 through 7.0
Description
The issue allows remote attackers to attach arbitrary files and send mail via a crafted Subject field. This is due to improper handling by the CFMAIL tag in applications that use ColdFusion.
Recommendations
For versions 6.0 through 7.0, update the CFMAIL tag handling to properly validate and sanitize the Subject field to prevent attachment of arbitrary files.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coldfusion