📦

coldfusion_professional

Vendor: macromedia

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 0 Remote Access
Total CVEs 4 Total Indexed
Avg. EPSS 3.98% Exploit Prob.
Latest CVE CVE-2003-1469 Dec 31

Security Vulnerability Index

Page 1 / 1
5.0 CVSS
CVE-2003-1469
Exploit Found

The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error message.

EPSS: 6.19%
5.0 CVSS

Buffer overflow in jrun.dll in ColdFusion MX, when used with IIS 4 or 5, allows remote attackers to cause a denial of service in IIS via (1) a long template file name or (2) a long HTTP header.

EPSS: 1.77%