Unrated severityNVD Advisory· Published Mar 1, 2000· Updated Apr 16, 2026
CVE-2000-0189
CVE-2000-0189
Description
ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files.
Affected products
3cpe:2.3:a:allaire:coldfusion_server:4.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:allaire:coldfusion_server:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:allaire:coldfusion_server:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:allaire:coldfusion_server:4.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.