Korean
<< Back
VID 22216
Severity 20
Port 80, ...
Protocol TCP
Class WWW
Detailed Description The ColdFusion MX Server has a path revealing vulnerability via a MS-DOS device name.
Macromedia ColdFusion is a web application server. ColdFusion version 5.0 and earlier on Windows systems allow a remote attacker to obtain sensitive information.
By submitting a web request for MS-DOS device name such as NUL, with a non-existant .cfm or .dbm file extension, a remote attacker would cause an error message to be returned that contains the full path to the Web root directory.

* References:
http://archives.neohapsis.com/archives/bugtraq/2002-04/0235.html

* Platforms Affected:
ColdFusion Server 4.0
ColdFusion Server 4.5
ColdFusion Server 5.0
Windows Any version
Recommendation Upgrade to the latest version of ColdFusion Serve from:
http://www.adobe.com/support/coldfusion/downloads.html
Related URL CVE-2002-0576 (CVE)
Related URL 4542 (SecurityFocus)
Related URL 8866 (ISS)