CVE-1999-0760
UnknownEPSS 1.74%
Last modified
CVE-1999-0760 is a vulnerability of currently unknown severity. Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges.. EPSS estimates a 1.74% chance of exploitation in the next 30 days.
Description
Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Allaire | Coldfusion Server | 2.0 |
| Allaire | Coldfusion Server | 3.0 |
| Allaire | Coldfusion Server | 3.0.1 |
| Allaire | Coldfusion Server | 3.1 |
| Allaire | Coldfusion Server | 3.1.1 |
| Allaire | Coldfusion Server | 3.1.2 |
| Allaire | Coldfusion Server | 4.0 |
| Allaire | Coldfusion Server | 4.0.1 |
References
- http://www.securityfocus.com/bid/550Patch, Vendor Advisory
- http://www.securityfocus.com/bid/550Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-1999-0760?
Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges.
How severe is CVE-1999-0760?
Severity scoring for CVE-1999-0760 is pending analysis. The EPSS model estimates a 1.74% probability of exploitation in the next 30 days.
How do I fix CVE-1999-0760?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 1999
- CVE-1999-0754The INN inndstart program allows local users to gain privile…
- CVE-1999-0755Windows NT RRAS and RAS clients cache a user's password even…
- CVE-1999-0756ColdFusion Administrator with Advanced Security enabled allo…
- CVE-1999-0757The ColdFusion CFCRYPT program for encrypting CFML templates…
- CVE-1999-0758Netscape Enterprise 3.5.1 and FastTrack 3.01 servers allow a…
- CVE-1999-0759Buffer overflow in FuseMAIL POP service via long USER and PA…
- CVE-1999-0761Buffer overflow in FreeBSD fts library routines allows local…
- CVE-1999-0762When Javascript is embedded within the TITLE tag, Netscape C…
- CVE-1999-0763NetBSD on a multi-homed host allows ARP packets on one netwo…
- CVE-1999-0764NetBSD allows ARP packets to overwrite static ARP entries.
- CVE-1999-0765SGI IRIX midikeys program allows local users to modify arbit…
- CVE-1999-0766The Microsoft Java Virtual Machine allows a malicious Java a…
Are you affected by CVE-1999-0760?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
