Adobe ColdFusion MX7 allows remote attackers to obtain sensitive information via a URL request (1) for a non-existent (a) JWS, (b) CFM, (c) CFML, or (d) CFC file, which displays the installation path in the resulting error message; or (2) to /CFIDE/administrator/login.cfm without a host, which can reveal the server's internal IP address in an HREF tag.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2006-12-12T20:00:00
Updated: 2024-08-07T20:26:46.591Z
Reserved: 2006-12-12T00:00:00
Link: CVE-2006-6482
Vulnrichment
No data.
NVD
Status : Modified
Published: 2006-12-12T20:28:00.000
Modified: 2024-11-21T00:22:47.537
Link: CVE-2006-6482
Redhat
No data.