Back

CVE-2005-4343

Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files and send mail via a crafted Subject field, which is not properly handled by the CFMAIL tag in applications that use ColdFusion, aka "CFMAIL injection Vulnerability".

Published: Dec 19, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (5)

Vendor Product Version
macromedia coldfusion 6.0
macromedia coldfusion 6.1
macromedia coldfusion 6.1
macromedia coldfusion 6.1
macromedia coldfusion 7.0

GitHub Security Advisory GHSA-gvph-v5gg-8pcr

Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 1.49%

Top 28% most likely to be exploited

Threat Score 20.4 / 100

Data Sources

NVD EPSS GitHub