Filtered by vendor Allaire Subscriptions
Total 24 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2001-1120 1 Allaire 1 Coldfusion Server 2025-04-03 N/A
Vulnerabilities in ColdFusion 2.0 through 4.5.1 SP 2 allow remote attackers to (1) read or delete arbitrary files, or (2) overwrite ColdFusion Server templates.
CVE-1999-0455 1 Allaire 1 Coldfusion Server 2025-04-03 N/A
The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.
CVE-1999-0477 1 Allaire 1 Coldfusion Server 2025-04-03 N/A
The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.
CVE-2002-0108 1 Allaire 1 Forums 2025-04-03 N/A
Allaire Forums 2.0.4 and 2.0.5 and Forums! 3.0 and 3.1 allows remote authenticated users to spoof messages as other users by modifying the hidden form fields for the name and e-mail address.