Show filters
23 Total Results
Displaying 21-23 of 23
Sort by:
Attacker Value
Unknown
CVE-2003-1469
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error message.
0
Attacker Value
Unknown
CVE-2002-1700
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.
0
Attacker Value
Unknown
CVE-2002-1309
Disclosure Date: November 29, 2002 (last updated February 22, 2025)
Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia ColdFusion 6.0 allows remote attackers to execute arbitrary via an HTTP GET request with a long .cfm file name.
0