CVE-2005-2481: Medium severity Macromedia Coldfusion Fusebox vulnerability
ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the "?" (question mark) character.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2481?
The severity of CVE-2005-2481 is considered moderate as it can lead to information disclosure.
How do I fix CVE-2005-2481?
To fix CVE-2005-2481, ensure proper input validation for the fuseaction parameter to prevent error messages from revealing sensitive information.
What information can be leaked by CVE-2005-2481?
CVE-2005-2481 can leak the full server path in error messages, potentially exposing sensitive server configurations.
Which versions of ColdFusion Fusebox are affected by CVE-2005-2481?
CVE-2005-2481 specifically affects ColdFusion Fusebox version 4.1.0.
Is CVE-2005-2481 exploitable remotely?
Yes, CVE-2005-2481 is exploitable remotely as it allows attackers to send specially crafted requests to leak sensitive information.