Vulnerability Name: | CCN-70076 | ||||||
Published: | 2011-09-26 | ||||||
Updated: | 2011-09-26 | ||||||
Summary: | Adobe ColdFusion could allow a remote attacker to obtain sensitive information. An attacker could send a specially-crafted URL request to multiple scripts using an invalid parameter to cause an error message to be returned containing the full installation path. An attacker could use this information to launch further attacks against the affected system. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||
CVSS v2 Severity: | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:UR)
| ||||||
Vulnerability Consequences: | Obtain Information | ||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Mon Sep 26 2011 XSS and FPD vulnerabilities in Adobe ColdFusion Source: CCN Type: Adobe ColdFusion Web site Adobe - Products : ColdFusion Source: CCN Type: BID-49787 Adobe ColdFusion Multiple Cross Site Scripting Vulnerabilities Source: XF Type: UNKNOWN coldfusion-multiple-path-disclosure(70076) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |