CVE-1999-0477

ColdFusion - File Upload

Title source: llm
STIX 2.1

Description

The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.

Exploits (1)

exploitdb WRITEUP VERIFIED
by rain.forest.puppy · textremotemultiple
https://www.exploit-db.com/exploits/19093

References (1)

Core 1
Core References
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/115

Scores

EPSS 0.0685
EPSS Percentile 91.5%

Details

Status published
Products (6)
allaire/coldfusion_server 2.0
allaire/coldfusion_server 3.0
allaire/coldfusion_server 3.01
allaire/coldfusion_server 3.11
allaire/coldfusion_server 3.12
allaire/coldfusion_server 4.0
Published Dec 25, 1999
Tracked Since Feb 18, 2026