VendorsAllairecoldfusion_server4.5
Vulnerabilities

Allaire Coldfusion Server 4.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2001-1120
Vulnerabilities in ColdFusion 2.0 through 4.5.1 SP 2 allow remote attackers to (1) read or delete arbitrary files, or (2) overwrite ColdFusion Server templates.
Published 2002-03-15 · Modified
6.4EPSS 0.019
CVE-2000-0538
ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a long login password.
Published 2000-10-13 · Modified
5.01 PoCEPSS 0.084
CVE-2002-0576
ColdFusion 5.0 and earlier on Windows systems allows remote attackers to determine the absolute pathname of .cfm or .dbm files via an HTTP request that contains an MS-DOS device name such as NUL, which leaks the pathname in an error message.
Published 2003-04-02 · Modified
5.0EPSS 0.027
CVE-2000-0189
ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files.
Published 2000-04-10 · Modified
5.0EPSS 0.019