ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the "?" (question mark) character.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-08-05T04:00:00

Updated: 2024-08-07T22:30:01.748Z

Reserved: 2005-08-05T00:00:00

Link: CVE-2005-2481

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2005-08-05T04:00:00.000

Modified: 2016-10-18T03:27:51.917

Link: CVE-2005-2481

cve-icon Redhat

No data.