First published: Tue Jun 18 2002(Updated: )
ColdFusion 5.0 and earlier on Windows systems allows remote attackers to determine the absolute pathname of .cfm or .dbm files via an HTTP request that contains an MS-DOS device name such as NUL, which leaks the pathname in an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =4.0 | |
Adobe ColdFusion | =4.5 | |
Adobe ColdFusion | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0576 is considered to be of medium severity due to its information disclosure risk.
To fix CVE-2002-0576, upgrade to a version of ColdFusion later than 5.0 that addresses this vulnerability.
CVE-2002-0576 affects ColdFusion 4.0, 4.5, and 5.0 running on Windows systems.
Yes, the information disclosure from CVE-2002-0576 could potentially aid attackers in launching more targeted attacks.
CVE-2002-0576 is classified as an information disclosure vulnerability.