CVE-2005-4343
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/12/2005
Last modified:
03/04/2025
Description
Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files and send mail via a crafted Subject field, which is not properly handled by the CFMAIL tag in applications that use ColdFusion, aka "CFMAIL injection Vulnerability".
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:macromedia:coldfusion:6.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:macromedia:coldfusion:6.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:macromedia:coldfusion:6.1:*:enterprise_with_jrun:*:*:*:*:* | ||
| cpe:2.3:a:macromedia:coldfusion:6.1:*:j2ee_application_server:*:*:*:*:* | ||
| cpe:2.3:a:macromedia:coldfusion:7.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/18078
- http://securitytracker.com/id?1015369=
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-12.html
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-14.html
- http://www.securityfocus.com/bid/15904
- http://www.vupen.com/english/advisories/2005/2948
- http://secunia.com/advisories/18078
- http://securitytracker.com/id?1015369=
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-12.html
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-14.html
- http://www.securityfocus.com/bid/15904
- http://www.vupen.com/english/advisories/2005/2948



