CVE-2005-4343

Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files and send mail via a crafted Subject field, which is not properly handled by the CFMAIL tag in applications that use ColdFusion, aka "CFMAIL injection Vulnerability".
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:macromedia:coldfusion:6.0:*:*:*:*:*:*:*
cpe:2.3:a:macromedia:coldfusion:6.1:*:*:*:*:*:*:*
cpe:2.3:a:macromedia:coldfusion:6.1:*:enterprise_with_jrun:*:*:*:*:*
cpe:2.3:a:macromedia:coldfusion:6.1:*:j2ee_application_server:*:*:*:*:*
cpe:2.3:a:macromedia:coldfusion:7.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2005-12-19 03:47

Updated : 2023-12-10 10:28


NVD link : CVE-2005-4343

Mitre link : CVE-2005-4343

CVE.ORG link : CVE-2005-4343


JSON object : View

Products Affected

macromedia

  • coldfusion