CVE

Id
3349  
CVE No.
CVE-2001-0535  
Status
Candidate  
Description
Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host"s domain, which allows remote attackers to conduct upload, read, or execute files by spoofing the "HTTP Host" (CGI.Host) variable in (1) the "Web Publish" example script, and (2) the "Email" example script.  
Phase
Proposed (20011012)  
Votes
ACCEPT(3) Armstrong, Baker, Cole | MODIFY(2) Foat, Frech | NOOP(1) Christey | REVIEWING(1) Wall  
Comments
Frech> XF:coldfusion-webpublish-execute-code(6790) | XF:coldfusion-email-view-files(6791) | Foat> Includes ColdFusion Server 4.x and earlier | Christey> Consider adding BID:3154