Search Results (24 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2000-0120 1 Allaire 1 Spectra 2025-04-03 N/A
The Remote Access Service invoke.cfm template in Allaire Spectra 1.0 allows users to bypass authentication via the bAuthenticated parameter.
CVE-2000-0297 1 Allaire 1 Forums 2025-04-03 N/A
Allaire Forums 2.0.5 allows remote attackers to bypass access restrictions to secure conferences via the rightAccessAllForums or rightModerateAllForums variables.
CVE-2000-0334 1 Allaire 1 Spectra 2025-04-03 N/A
The Allaire Spectra container editor preview tool does not properly enforce object security, which allows an attacker to conduct unauthorized activities via an object-method that is added to the container object with a publishing rule.
CVE-1999-0477 1 Allaire 1 Coldfusion Server 2025-04-03 N/A
The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.