Vulnerability Name: | CCN-16055 | ||||||
Published: | 2003-07-08 | ||||||
Updated: | 2003-07-08 | ||||||
Summary: | Macromedia ColdFusion MX and Macromedia JRun version 4.0 running on Apache HTTP Server versions 1.3.x and 2.0 on Microsoft Windows platforms could allow a remote attacker to obtain sensitive information. By sending a specially-crafted URL request containing an appended encoded space character, a remote attacker could view the source code of known .cfm, .cfc, .cfml or .jsp files. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||
CVSS v2 Severity: | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||
Vulnerability Consequences: | Obtain Information | ||||||
References: | Source: CCN Type: SA9222 Macromedia ColdFusion MX / JRun Source Code Disclosure Vulnerability Source: CCN Type: SECTRACK ID: 1007161 Macromedia JRun Discloses Page Source Code to Remote Users Source: CCN Type: Macromedia Security Bulletin MPSB03-04 MPSB03-04 Patch for Apache 1.3.x, 2.0 View Source Vulnerability in ColdFusion MX and JRun 4.0 on Windows Source: CCN Type: BID-8136 Macromedia Apache Web Server Encoded Space Source Disclosure Vulnerability Source: XF Type: UNKNOWN coldfusion-jrun-source-disclosure(16055) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |