The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/115 | Vendor Advisory |
Configurations
Information
Published : 1999-12-24 21:00
Updated : 2008-09-09 05:34
NVD link : CVE-1999-0455
Mitre link : CVE-1999-0455
JSON object : View
CWE
Products Affected
allaire
- coldfusion_server