VendorsAllairecoldfusion_server4.0.1
Vulnerabilities

Allaire Coldfusion Server 4.0.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-1999-0760
Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges.
Published 2001-05-07 · Modified
10.0EPSS 0.017
CVE-2000-0057
Cold Fusion CFCACHE tag places temporary cache files within the web document root, allowing remote attackers to obtain sensitive system information.
Published 2000-04-18 · Modified
7.51 PoCEPSS 0.055
CVE-2001-1120
Vulnerabilities in ColdFusion 2.0 through 4.5.1 SP 2 allow remote attackers to (1) read or delete arbitrary files, or (2) overwrite ColdFusion Server templates.
Published 2002-03-15 · Modified
6.4EPSS 0.019
CVE-2000-0538
ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a long login password.
Published 2000-10-13 · Modified
5.01 PoCEPSS 0.084
CVE-2000-0189
ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files.
Published 2000-04-10 · Modified
5.0EPSS 0.019
CVE-1999-0756
ColdFusion Administrator with Advanced Security enabled allows remote users to stop the ColdFusion server via the Start/Stop utility.
Published 2001-09-18 · Modified
5.0EPSS 0.013