PT-2006-3028 · Application Dynamics · Cartweaver Coldfusion

Published

2006-04-26

·

Updated

2017-07-20

·

CVE-2006-2047

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Application Dynamics Cartweaver ColdFusion version 2.16.11 and earlier
Description The issue allows remote attackers to obtain sensitive information via invalid parameters in certain pages. This can be achieved by manipulating the secondary, PageNum Results, category, or keywords parameters in the "Results.cfm" page, or the ProdID parameter in the "Details.cfm" page, which can reveal the path in various error messages. The behavior related to the category, keywords, and ProdID parameters might be a result of SQL injection.
Recommendations For Application Dynamics Cartweaver ColdFusion version 2.16.11 and earlier, consider restricting access to the "Results.cfm" and "Details.cfm" pages until a fix is available. As a temporary workaround, avoid using the secondary, PageNum Results, category, keywords, and ProdID parameters in the affected API endpoints.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2047

Affected Products

Cartweaver Coldfusion