CVE Database
/

CVE-2011-0736

Back to search

CVE-2011-0736

Published: Feb 1, 2011

Modified: Jan 21, 2025

PUBLISHED

Description

Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database structure via an id=- query to a .cfm file. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure

VendorProductVersions

n/a

n/a

affected
n/a

References

70780
vdb-entry
x_refsource_OSVDB
20110128 Vulnerabilities in Adobe ColdFusion
mailing-list
x_refsource_FULLDISC

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now