5
CVE-2005-2481
- EPSS 1.19%
- Veröffentlicht 05.08.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:14:58
- Erkennungen
ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the "?" (question mark) character.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Macromedia ≫ Coldfusion Fusebox Version 4.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.19% | 0.64 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://marc.info/?l=bugtraq&m=112309656102615&w=2