CVE-1999-0477
ColdFusion Server - Unauthenticated Arbitrary File Upload via openfile.cfm
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-1999-0477. PoCs published by rain.forest.puppy.
AI-analyzed exploit summary This exploit describes a directory traversal and arbitrary file deletion vulnerability in ColdFusion. It allows an attacker to read, delete, or upload files on the server by manipulating the OpenFilePath parameter.
Description
The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.
Exploits (1)
This exploit describes a directory traversal and arbitrary file deletion vulnerability in ColdFusion. It allows an attacker to read, delete, or upload files on the server by manipulating the OpenFilePath parameter.