5
CVSSv2

CVE-2000-0189

Published: 01/03/2000 Updated: 10/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

ColdFusion Server 4.x allows remote malicious users to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files.

Vulnerable Product Search on Vulmon Subscribe to Product

allaire coldfusion server 4.0

allaire coldfusion server 4.0.1

allaire coldfusion server 4.5