Back to search
CVE-2006-5858
Published: Jan 10, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
Adobe ColdFusion MX 7 through 7.0.2, and JRun 4, when run on Microsoft IIS, allows remote attackers to read arbitrary files, list directories, or read source code via a double URL-encoded NULL byte in a ColdFusion filename, such as a CFM file.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.adobe.com/support/security/bulletins/apsb07-02.html
x_refsource_CONFIRM
20070121 Adobe ColdFusion Information Disclosure
mailing-list
x_refsource_BUGTRAQ
23668
third-party-advisory
x_refsource_SECUNIA
20070109 Adobe Macromedia ColdFusion Source Code Disclosure Vulnerability
third-party-advisory
x_refsource_IDEFENSE
1017490
vdb-entry
x_refsource_SECTRACK
21978
vdb-entry
x_refsource_BID
32123
vdb-entry
x_refsource_OSVDB
ADV-2007-0116
vdb-entry
x_refsource_VUPEN
coldfusion-urlparsing-info-disclosure(31411)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now