vendor:
ColdFusion
by:
SecurityFocus
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: ColdFusion
Affected Version From: Allaire ColdFusion 4.5.1
Affected Version To: Allaire ColdFusion 4.5.1
Patch Exists: NO
Related CWE: N/A
CPE: a:allaire:coldfusion:4.5.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2002
Denial of Service in Allaire ColdFusion 4.5.1
Due to a faulty mechanism in the password parsing implementation in authentication requests, it is possible to launch a denial of service attack against Allaire ColdFusion 4.5.1 or previous by inputting a string of over 40 000 characters to the password field in the Administrator login page. CPU utilization could reach up to 100%, bringing the program to halt. The default form for the login page would prevent such an attack. However, a malicious user could download the form locally to their hard drive, modify HTML tag fields, and be able to submit the 40 000 character string to the ColdFusion Server.
Mitigation:
Restarting the application would be required in order to regain normal functionality.