Description
Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files and send mail via a crafted Subject field, which is not properly handled by the CFMAIL tag in applications that use ColdFusion, aka "CFMAIL injection Vulnerability".
Affected products
- macromedia / coldfusion6.0 – 6.0
- macromedia / coldfusion6.1 – 6.1
- macromedia / coldfusion6.1 – 6.1
- macromedia / coldfusion6.1 – 6.1
- macromedia / coldfusion7.0 – 7.0
References
- VENDOR_ADVISORYhttp://secunia.com/advisories/18078
- MISChttp://www.macromedia.com/devnet/security/security_zone/mpsb05-12.html
- MISChttp://www.macromedia.com/devnet/security/security_zone/mpsb05-14.html
- MISChttp://www.securityfocus.com/bid/15904
- MISChttp://securitytracker.com/id?1015369
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2005/2948