Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
coldfusion vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2001-0535
Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allows remote malicious users to conduct upload, read, or execute files by spoofing the "HTTP Host" (CGI.Host) variable i...
Macromedia Coldfusion Server 4.x
7.5
CVSSv2
CVE-2001-1427
Unknown vulnerability in ColdFusion Server 2.0 up to and including 4.5.1 SP2 allows remote malicious users to overwrite templates with zero byte files via unknown attack vectors.
Macromedia Coldfusion 4.0
Macromedia Coldfusion 4.0.1
Macromedia Coldfusion 3.0.1
Macromedia Coldfusion 3.1
Macromedia Coldfusion 4.5.1
Macromedia Coldfusion 2.0
Macromedia Coldfusion 3.0
Macromedia Coldfusion 4.5
Macromedia Coldfusion 3.1.1
Macromedia Coldfusion 3.1.2
7.5
CVSSv2
CVE-1999-0923
Sample runnable code snippets in ColdFusion Server 4.0 allow remote malicious users to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls.
Allaire Coldfusion Server 4.0
7.5
CVSSv2
CVE-2000-0057
Cold Fusion CFCACHE tag places temporary cache files within the web document root, allowing remote malicious users to obtain sensitive system information.
Allaire Coldfusion Server 4.0.1
Allaire Coldfusion Server 4.0
1 EDB exploit
7.5
CVSSv2
CVE-1999-1124
HTTP Client application in ColdFusion allows remote malicious users to bypass access restrictions for web pages on other ports by providing the target page to the mainframeset.cfm application, which requests the page from the server, making it look like the request is coming from...
Allaire Coldfusion
7.5
CVSSv2
CVE-1999-0477
The Expression Evaluator in the ColdFusion Application Server allows a remote malicious user to upload files to the server via openfile.cfm, which does not restrict access to the server properly.
Allaire Coldfusion Server 2.0
Allaire Coldfusion Server 3.0
Allaire Coldfusion Server 3.01
Allaire Coldfusion Server 3.11
Allaire Coldfusion Server 3.12
Allaire Coldfusion Server 4.0
1 EDB exploit
7.5
CVSSv2
CVE-1999-0455
The Expression Evaluator sample application in ColdFusion allows remote malicious users to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.
Allaire Coldfusion Server 4.0
1 EDB exploit
7.2
CVSSv2
CVE-2020-10145
The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By default, unprivileged users can create files in this directory structure, which creates a privilege-escalation vulnerability.
Adobe Coldfusion 2018
Adobe Coldfusion 2016
Adobe Coldfusion 2021
7.2
CVSSv2
CVE-2008-4831
Unspecified vulnerability in Adobe ColdFusion 8 and 8.0.1 and ColdFusion MX 7.0.2 allows local users to bypass sandbox restrictions, and obtain sensitive information or possibly gain privileges, via unknown vectors.
Adobe Coldfusion 8.0
Adobe Coldfusion 8.0.1
Adobe Coldfusion 7.2
7.2
CVSSv2
CVE-2007-1874
Adobe ColdFusion MX 7 for Linux and Solaris uses insecure permissions for certain scripts and directories, which allows local users to execute arbitrary code or obtain sensitive information via the (1) CFMX7DreamWeaverExtensions.mxp, (2) CFReportBuilderInstaller.exe, (3) .com.zer...
Adobe Coldfusion 7.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
CVE-2006-4304
wireless
CVE-2023-23022
local file inclusion
CVE-2024-27058
CVE-2024-33820
open redirect
CVE-2024-27079
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »