| VID |
22216 |
| Severity |
20 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
WWW |
| Detailed Description |
The ColdFusion MX Server has a path revealing vulnerability via a MS-DOS device name. Macromedia ColdFusion is a web application server. ColdFusion version 5.0 and earlier on Windows systems allow a remote attacker to obtain sensitive information. By submitting a web request for MS-DOS device name such as NUL, with a non-existant .cfm or .dbm file extension, a remote attacker would cause an error message to be returned that contains the full path to the Web root directory.
* References: http://archives.neohapsis.com/archives/bugtraq/2002-04/0235.html
* Platforms Affected: ColdFusion Server 4.0 ColdFusion Server 4.5 ColdFusion Server 5.0 Windows Any version |
| Recommendation |
Upgrade to the latest version of ColdFusion Serve from: http://www.adobe.com/support/coldfusion/downloads.html |
| Related URL |
CVE-2002-0576 (CVE) |
| Related URL |
4542 (SecurityFocus) |
| Related URL |
8866 (ISS) |
|