7.5
CVSSv2

CVE-1999-0455

Published: 25/12/1999 Updated: 09/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Expression Evaluator sample application in ColdFusion allows remote malicious users to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.

Vulnerable Product Search on Vulmon Subscribe to Product

allaire coldfusion server 4.0

Exploits

source: wwwsecurityfocuscom/bid/115/info To display and delete any file on the system use an URL of the following form: wwwvictimtest/cfdocs/expeval/ExprCalccfm?OpenFilePath=C:\the\target\file To upload files to the sever first find out the location of the sample code on the server by uploading a dummy file by using www ...