VYPR
Unrated severityNVD Advisory· Published Dec 31, 2006· Updated Jun 16, 2026

CVE-2006-5858

CVE-2006-5858

Description

Adobe ColdFusion MX 7 through 7.0.2, and JRun 4, when run on Microsoft IIS, allows remote attackers to read arbitrary files, list directories, or read source code via a double URL-encoded NULL byte in a ColdFusion filename, such as a CFM file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*:*range: >=7.0,<=7.0.2
    • (no CPE)range: 7 through 7.0.2
  • Adobe Inc./Jrun2 versions
    cpe:2.3:a:adobe:jrun:4.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:jrun:4.0:*:*:*:*:*:*:*
    • (no CPE)range: 4

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.