Vulnerabilities > CVE-2004-2505 - Denial Of Service vulnerability in Macromedia ColdFusion MX Oversized Error Message

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
macromedia
exploit available

Summary

Macromedia ColdFusion MX before 6.1 does not restrict the size of error messages, which allows remote attackers to cause a denial of service (memory consumption and crash) by sending repeated GET or POST requests that trigger error messages that use long strings of data.

Vulnerable Configurations

Part Description Count
Application
Macromedia
2

Exploit-Db

descriptionMacromedia ColdFusion MX 6.0 Oversized Error Message Denial Of Service Vulnerability. CVE-2004-2505. Dos exploits for multiple platform
idEDB-ID:24013
last seen2016-02-02
modified2004-04-17
published2004-04-17
reporterK. K. Mookhey
sourcehttps://www.exploit-db.com/download/24013/
titleMacromedia ColdFusion MX 6.0 - Oversized Error Message Denial of Service Vulnerability