CVE-1999-0455 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 5.8% (pctl 93)
Patch early
A public exploit exists.
Description
The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 5.85% — more likely to be exploited than 93% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 1999-12-25 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| allaire | coldfusion server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Allaire ColdFusion Server 4.0 - Remote File Display / Deletion / Upload / Execution | 1998-12-25 |
→ the Explorer · watch your stack · NVD