Macromedia ColdFusion MX Error Message Path Disclosure Vulnerability
BID:7443
Info
Macromedia ColdFusion MX Error Message Path Disclosure Vulnerability
| Bugtraq ID: | 7443 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 26 2003 12:00AM |
| Updated: | Apr 26 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Network Intelligence India Pvt. Ltd." <[email protected]>. |
| Vulnerable: |
Macromedia ColdFusion Server MX 6.0 Macromedia ColdFusion Server MX Professional Macromedia ColdFusion Server MX Enterprise Macromedia ColdFusion Server MX Developer |
| Not Vulnerable: | |
Discussion
Macromedia ColdFusion MX Error Message Path Disclosure Vulnerability
A vulnerability has been reported for Macromedia ColdFusion MX that may reveal the physical path information to attackers.
When certain malformed URL requests are received by the server, an error message is returned containing the full path of the ColdFusion installation.
A vulnerability has been reported for Macromedia ColdFusion MX that may reveal the physical path information to attackers.
When certain malformed URL requests are received by the server, an error message is returned containing the full path of the ColdFusion installation.
References
Macromedia ColdFusion MX Error Message Path Disclosure Vulnerability
References:
References:
- Macromedia Homepage (Macromedia)
- NII Advisory - Path Disclosure in Cold Fusion MX Server ("Network Intelligence India Pvt. Ltd."
)