CVE-2004-0928

3 documents3 sources
Severity
5.0MEDIUM
EPSS
20.9%
top 4.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 5
Latest updateApr 29

Description

The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE allows remote attackers to bypass authentication and view source files, such as .asp, .pl, and .php files, via an HTTP request that ends in ";.cfm".

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

NVDmacromedia/jrun3.0, 3.1, 4.0+2
NVDmacromedia/coldfusion6.0, 6.1+1
NVDhitachi/cosminexus_serverweb_01-01_1, web_01-01_2+1
NVDhitachi/cosminexus_enterprise01_01_1, 01_02_2+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hcc4-r9c5-cv8f: The Microsoft IIS Connector in JRun 42022-04-29
CVEList
CVE-2004-0928: The Microsoft IIS Connector in JRun 42005-04-21
CVE-2004-0928 (MEDIUM CVSS 5) | The Microsoft IIS Connector in JRun | cvebase.io