The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/115 | Vendor Advisory |
http://www.securityfocus.com/bid/115 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 1999-12-25 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-1999-0455
Mitre link : CVE-1999-0455
CVE.ORG link : CVE-1999-0455
JSON object : View
Products Affected
allaire
- coldfusion_server
CWE