CVE-2001-0535
Last modified
CVE-2001-0535 is a vulnerability of currently unknown severity. Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allows remote attackers to conduct upload, read, or execute files by spoofing the "HTTP Host" (CGI.Host) variable in (1) the "Web Publish" example script, and (2) the "Email" example script.. EPSS estimates a 1.96% chance of exploitation in the next 30 days.
Description
Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allows remote attackers to conduct upload, read, or execute files by spoofing the "HTTP Host" (CGI.Host) variable in (1) the "Web Publish" example script, and (2) the "Email" example script.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Macromedia | Coldfusion Server | 4.x |
References
- http://www.allaire.com/Handlers/index.cfm?ID=21700Vendor Advisory
- http://xforce.iss.net/alerts/advise92.phpVendor Advisory
- http://www.allaire.com/Handlers/index.cfm?ID=21700Vendor Advisory
- http://xforce.iss.net/alerts/advise92.phpVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-0535?
How severe is CVE-2001-0535?
How do I fix CVE-2001-0535?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2001
- CVE-2001-0527DCScripts DCForum versions 2000 and earlier allow a remote a…
- CVE-2001-0528Oracle E-Business Suite Release 11i Applications Desktop Int…
- CVE-2001-0529OpenSSH version 2.9 and earlier, with X forwarding enabled, …
- CVE-2001-0530Spearhead NetGAP 200 and 300 before build 78 allow a remote …
- CVE-2001-0533Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x …
- CVE-2001-0534Multiple buffer overflows in RADIUS daemon radiusd in (1) Me…
- CVE-2001-0537HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to b…
- CVE-2001-0538Microsoft Outlook View ActiveX Control in Microsoft Outlook …
- CVE-2001-0540Memory leak in Terminal servers in Windows NT and Windows 20…
- CVE-2001-0541Buffer overflow in Microsoft Windows Media Player 7.1 and ea…
- CVE-2001-0542Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow …
- CVE-2001-0543Memory leak in NNTP service in Windows NT 4.0 and Windows 20…
Are you affected by CVE-2001-0535?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
