Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls.
https://euvd.enisa.europa.eu/vulnerability/EUVD-1999-0904
http://www.allaire.com/handlers/index.cfm?ID=8739&Method=Full