Unrated severityNVD Advisory· Published Jun 18, 2002· Updated Apr 16, 2026
CVE-2002-0576
CVE-2002-0576
Description
ColdFusion 5.0 and earlier on Windows systems allows remote attackers to determine the absolute pathname of .cfm or .dbm files via an HTTP request that contains an MS-DOS device name such as NUL, which leaks the pathname in an error message.
Affected products
3cpe:2.3:a:allaire:coldfusion_server:4.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:allaire:coldfusion_server:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:allaire:coldfusion_server:4.5:*:*:*:*:*:*:*
- cpe:2.3:a:allaire:coldfusion_server:5.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.iss.net/security_center/static/8866.phpnvdPatchVendor Advisory
- www.macromedia.com/v1/handlers/index.cfmnvdPatchVendor Advisory
- www.securityfocus.com/bid/4542nvdPatchVendor Advisory
- archives.neohapsis.com/archives/vulnwatch/2002-q2/0028.htmlnvd
- online.securityfocus.com/archive/1/268263nvd
- www.osvdb.org/3337nvd
News mentions
0No linked articles in our index yet.