7.5

CVE-1999-0477

The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AllaireColdfusion Server Version2.0
AllaireColdfusion Server Version3.0
AllaireColdfusion Server Version3.01
AllaireColdfusion Server Version3.11
AllaireColdfusion Server Version3.12
AllaireColdfusion Server Version4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.85% 0.905
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P