PT-2006-3028 · Application Dynamics · Cartweaver Coldfusion

Publicado

2006-04-26

·

Atualizado

2017-07-20

·

CVE-2006-2047

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Application Dynamics Cartweaver ColdFusion version 2.16.11 and earlier
Description The issue allows remote attackers to obtain sensitive information via invalid parameters in certain pages. This can be achieved by manipulating the secondary, PageNum Results, category, or keywords parameters in the "Results.cfm" page, or the ProdID parameter in the "Details.cfm" page, which can reveal the path in various error messages. The behavior related to the category, keywords, and ProdID parameters might be a result of SQL injection.
Recommendations For Application Dynamics Cartweaver ColdFusion version 2.16.11 and earlier, consider restricting access to the "Results.cfm" and "Details.cfm" pages until a fix is available. As a temporary workaround, avoid using the secondary, PageNum Results, category, keywords, and ProdID parameters in the affected API endpoints.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2047

Produtos afetados

Cartweaver Coldfusion