Macromedia ColdFusion MX 7.0

CPE Details

Macromedia ColdFusion MX 7.0
7.0
2007-08-23
19h16 +00:00
2008-04-01
14h13 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:macromedia:coldfusion:7.0:*:*:*:*:*:*:*

Informations

Vendor

macromedia

Product

coldfusion

Version

7.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2003-1469 2007-10-24 21h00 +00:00 The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error message.
5
CVE-2006-3979 2006-08-09 08h00 +00:00 The AdminAPI of ColdFusion MX 7 allows attackers to bypass authentication by using "programmatic access" to the adminAPI instead of the ColdFusion Administrator.
7.2
CVE-2005-4342 2005-12-17 22h00 +00:00 ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager is disabled, which might allow remote attackers to "bypass security controls," aka "JRun Clustered Sandbox Security Vulnerability."
7.5
CVE-2005-4343 2005-12-17 22h00 +00:00 Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files and send mail via a crafted Subject field, which is not properly handled by the CFMAIL tag in applications that use ColdFusion, aka "CFMAIL injection Vulnerability".
5
CVE-2005-4344 2005-12-17 22h00 +00:00 Adobe (formerly Macromedia) ColdFusion MX 7.0 does not honor when the CFOBJECT /CreateObject(Java) setting is disabled, which allows local users to create an object despite the specified configuration.
2.1
CVE-2005-4345 2005-12-17 22h00 +00:00 Adobe (formerly Macromedia) ColdFusion MX 7.0 exposes the password hash of the Administrator in an API call, which allows local developers to obtain the hash and gain privileges.
7.2
CVE-2005-2306 2005-07-19 02h00 +00:00 Race condition in Macromedia JRun 4.0, ColdFusion MX 6.1 and 7.0, when under heavy load, causes JRun to assign a duplicate authentication token to multiple sessions, which could allow authenticated users to gain privileges as other users.
3.7
CVE-2002-1992 2005-07-14 04h00 +00:00 Buffer overflow in jrun.dll in ColdFusion MX, when used with IIS 4 or 5, allows remote attackers to cause a denial of service in IIS via (1) a long template file name or (2) a long HTTP header.
5
CVE-2005-1555 2005-05-14 02h00 +00:00 Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page.
4.3