6.4
CVSSv2

CVE-2005-4384

Published: 20/12/2005 Updated: 20/07/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

CitySoft Community Enterprise 4.x allows remote malicious users to obtain the full path of the server via an invalid (1) fuseaction parameter to index.cfm and (2) documentid parameter to document/docWindow.cfm.

Vulnerable Product Search on Vulmon Subscribe to Product

citysoft community enterprise 4.x