7.5
CVSSv2

CVE-1999-0477

Published: 25/12/1999 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Expression Evaluator in the ColdFusion Application Server allows a remote malicious user to upload files to the server via openfile.cfm, which does not restrict access to the server properly.

Vulnerable Product Search on Vulmon Subscribe to Product

allaire coldfusion server 2.0

allaire coldfusion server 3.0

allaire coldfusion server 3.01

allaire coldfusion server 3.11

allaire coldfusion server 3.12

allaire coldfusion server 4.0

Exploits

source: wwwsecurityfocuscom/bid/115/info To display and delete any file on the system use an URL of the following form: wwwvictimtest/cfdocs/expeval/ExprCalccfm?OpenFilePath=C:\the\target\file To upload files to the sever first find out the location of the sample code on the server by uploading a dummy file by using www ...