VulnerabilityModified
CVE-1999-0455
The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.
HIGH 7.5EPSS 5.85%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 5.85% probability · 93th percentile
- CISA KEV
- Not listed
- Affected
- allaire/coldfusion server
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/115Vendor Advisory
- http://www.securityfocus.com/bid/115Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.