PT-2005-3386 · Adobe · Coldfusion Fusebox
N.N.P
·
Published
2005-08-05
·
Updated
2016-10-18
·
CVE-2005-2481
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ColdFusion Fusebox version 4.1.0
Description
The issue allows remote attackers to obtain sensitive information via an invalid
fuseaction parameter. This occurs because the parameter leaks the full server path in an error message when, for example, the "?" (question mark) character is used.Recommendations
For ColdFusion Fusebox version 4.1.0, consider restricting access to the
fuseaction parameter to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using invalid characters in the fuseaction parameter to prevent error messages that could leak sensitive information. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coldfusion Fusebox