CVE-2002-0576
published 2002-06-18CVE-2002-0576: ColdFusion 5.0 and earlier on Windows systems allows remote attackers to determine the absolute pathname of .cfm or .dbm files via an HTTP request that…
PriorityP414medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.65%
83.8th percentile
ColdFusion 5.0 and earlier on Windows systems allows remote attackers to determine the absolute pathname of .cfm or .dbm files via an HTTP request that contains an MS-DOS device name such as NUL, which leaks the pathname in an error message.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| allaire | coldfusion_server | — | — |
| allaire | coldfusion_server | — | — |
| allaire | coldfusion_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0028.htmlhttp://online.securityfocus.com/archive/1/268263http://www.iss.net/security_center/static/8866.phphttp://www.macromedia.com/v1/handlers/index.cfm?ID=22906http://www.osvdb.org/3337http://www.securityfocus.com/bid/4542http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0028.htmlhttp://online.securityfocus.com/archive/1/268263http://www.iss.net/security_center/static/8866.phphttp://www.macromedia.com/v1/handlers/index.cfm?ID=22906http://www.osvdb.org/3337http://www.securityfocus.com/bid/4542
2002-06-18
Published