Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
coldfusion vulnerabilities and exploits
(subscribe to this query)
578
VMScore
CVE-2018-7486
Blue River Mura CMS before v7.0.7029 supports inline function calls with an [m] tag and [/m] end tag, without proper restrictions on file types or pathnames, which allows remote malicious users to execute arbitrary code via an [m]$.dspinclude("../pathname/executable.jpeg&quo...
Blueriver Muracms
570
VMScore
CVE-2018-15960
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and previous versions, and Update 14 and previous versions have a use of a component with a known vulnerability vulnerability. Successful exploitation could lead to arbitrary file overwrite.
Adobe Coldfusion 11.0
Adobe Coldfusion 2016
Adobe Coldfusion 2018
570
VMScore
CVE-2001-1120
Vulnerabilities in ColdFusion 2.0 up to and including 4.5.1 SP 2 allow remote malicious users to (1) read or delete arbitrary files, or (2) overwrite ColdFusion Server templates.
Allaire Coldfusion Server 3.1
Allaire Coldfusion Server 3.1.1
Allaire Coldfusion Server 2.0
Allaire Coldfusion Server 4.0.1
Allaire Coldfusion Server 4.5
Allaire Coldfusion Server 3.1.2
Allaire Coldfusion Server 4.0
Allaire Coldfusion Server 3.0
Allaire Coldfusion Server 3.0.1
Allaire Coldfusion Server 4.5.1
Allaire Coldfusion Server 4.5.1 Sp1
Allaire Coldfusion Server 4.5.1 Sp2
516
VMScore
CVE-2009-1878
Session fixation vulnerability in Adobe ColdFusion 8.0.1 and previous versions allows remote malicious users to hijack web sessions via unspecified vectors.
Adobe Coldfusion 7.2
Adobe Coldfusion 7.0
Adobe Coldfusion 6.0
Adobe Coldfusion 7.0.2
Adobe Coldfusion 7.0.1
Adobe Coldfusion 8.0
Adobe Coldfusion 8.1
Adobe Coldfusion 6.1
Adobe Coldfusion
516
VMScore
CVE-2006-2364
Cross-site scripting (XSS) vulnerability in the validation feature in Macromedia ColdFusion 5 and previous versions allows remote malicious users to inject arbitrary web script or HTML via a "_required" field when the associated normal field is missing or empty, which i...
Macromedia Coldfusion 5.0
505
VMScore
CVE-2013-3336
Unspecified vulnerability in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote malicious users to read arbitrary files via unknown vectors.
Adobe Coldfusion 9.0
Adobe Coldfusion 10.0
Adobe Coldfusion 9.0.1
Adobe Coldfusion 9.0.2
1 EDB exploit
1 Article
505
VMScore
CVE-2008-6580
The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access control, which allows remote malicious users to download the database via a direct request to (1) makered.mdb and (2) makered97.mdb.
Funscripts Red Reservations -
1 EDB exploit
505
VMScore
CVE-2004-2505
Macromedia ColdFusion MX prior to 6.1 does not restrict the size of error messages, which allows remote malicious users to cause a denial of service (memory consumption and crash) by sending repeated GET or POST requests that trigger error messages that use long strings of data.
Macromedia Coldfusion 5.0
Macromedia Coldfusion 6.0
1 EDB exploit
505
VMScore
CVE-2003-1469
The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote malicious users to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error message.
Macromedia Coldfusion 6.0
Macromedia Coldfusion Professional
Macromedia Coldfusion
1 EDB exploit
505
VMScore
CVE-2000-0538
ColdFusion Administrator for ColdFusion 4.5.1 and previous versions allows remote malicious users to cause a denial of service via a long login password.
Allaire Coldfusion Server 3.01
Allaire Coldfusion Server 3.1
Allaire Coldfusion Server 4.0
Allaire Coldfusion Server 4.0.1
Allaire Coldfusion Server 3.11
Allaire Coldfusion Server 3.12
Allaire Coldfusion Server 2.0
Allaire Coldfusion Server 3.0
Allaire Coldfusion Server 4.5
Allaire Coldfusion Server 4.5.1
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »