Security Advisory

CVE-2005-4343

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2005-12-17 23:00:00
Last updated 2024-08-07 23:38:51
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files and send mail via a crafted Subject field, which is not properly handled by the CFMAIL tag in applications that use ColdFusion, aka "CFMAIL injection Vulnerability".