CVE
- Id
- 475
- CVE No.
- CVE-1999-0477
- Status
- Candidate
- Description
- The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.
- Phase
- Modified (19991210-01)
- Votes
- ACCEPT(4) Baker, Christey, Frech, Ozancin | REJECT(1) Wall
- Comments
- Wall> Duplicate of 0455 | Christey> CVE-1999-0477 and CVE-1999-0455 were discovered at different | times. Also, the attack was different. So "Same Attack" and | "Same Time of Discovery" dictate that these should remain | separate.