CVE-2005-4343
5
CVSS SCORE
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N
Description
Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files and send mail via a crafted Subject field, which is not properly handled by the CFMAIL tag in applications that use ColdFusion, aka "CFMAIL injection Vulnerability".
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Confidentiality
None
Integrity
P
Availability
None
Affected Software Configurations
- a macromedia coldfusion 6.0 * * * * * * *
- a macromedia coldfusion 6.1 * * * * * * *
- a macromedia coldfusion 6.1 * enterprise_with_jrun * * * * *
- a macromedia coldfusion 6.1 * j2ee_application_server * * * * *
- a macromedia coldfusion 7.0 * * * * * * *
Weaknesses (CWE)
- NVD-CWE-Other
References & External Links
- http://secunia.com/advisories/18078
- http://securitytracker.com/id?1015369
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-12.html
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-14.html
- http://www.securityfocus.com/bid/15904
- http://www.vupen.com/english/advisories/2005/2948
- http://secunia.com/advisories/18078
- http://securitytracker.com/id?1015369
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-12.html
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-14.html
- http://www.securityfocus.com/bid/15904
- http://www.vupen.com/english/advisories/2005/2948