CVE Vulnerabilities

CVE-2000-0189

Published: Mar 01, 2000 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files.

Affected Software

NameVendorStart VersionEnd Version
Coldfusion_serverAllaire4.0 (including)4.0 (including)
Coldfusion_serverAllaire4.0.1 (including)4.0.1 (including)
Coldfusion_serverAllaire4.5 (including)4.5 (including)

References