Search Results (24 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2000-0189 1 Allaire 1 Coldfusion Server 2025-04-03 N/A
ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files.
CVE-2000-0382 1 Allaire 1 Clustercats 2025-04-03 N/A
ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection, which may provide sensitive information to the redirected site.
CVE-2002-0576 1 Allaire 1 Coldfusion Server 2025-04-03 N/A
ColdFusion 5.0 and earlier on Windows systems allows remote attackers to determine the absolute pathname of .cfm or .dbm files via an HTTP request that contains an MS-DOS device name such as NUL, which leaks the pathname in an error message.
CVE-1999-0922 1 Allaire 1 Coldfusion Server 2025-04-03 N/A
An example application in ColdFusion Server 4.0 allows remote attackers to view source code via the sourcewindow.cfm file.