CVE Vulnerabilities

CVE-2002-0576

Published: Jun 18, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

ColdFusion 5.0 and earlier on Windows systems allows remote attackers to determine the absolute pathname of .cfm or .dbm files via an HTTP request that contains an MS-DOS device name such as NUL, which leaks the pathname in an error message.

Affected Software

NameVendorStart VersionEnd Version
Coldfusion_serverAllaire4.0 (including)4.0 (including)
Coldfusion_serverAllaire4.5 (including)4.5 (including)
Coldfusion_serverAllaire5.0 (including)5.0 (including)

References