5
CVE-2005-4343
- EPSS 1.47%
- Published 19.12.2005 03:47:00
- Last modified 03.04.2025 01:03:51
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files and send mail via a crafted Subject field, which is not properly handled by the CFMAIL tag in applications that use ColdFusion, aka "CFMAIL injection Vulnerability".
Data is provided by the National Vulnerability Database (NVD)
Macromedia ≫ Coldfusion Version6.0
Macromedia ≫ Coldfusion Version6.1
Macromedia ≫ Coldfusion Version6.1 Editionenterprise_with_jrun
Macromedia ≫ Coldfusion Version6.1 Editionj2ee_application_server
Macromedia ≫ Coldfusion Version7.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.47% | 0.791 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|