ColdFusion Server 4.x allows remote malicious users to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
allaire coldfusion server 4.0 |
||
allaire coldfusion server 4.0.1 |
||
allaire coldfusion server 4.5 |