Unrated severityNVD Advisory· Published Dec 12, 2006· Updated Apr 23, 2026
CVE-2006-6482
CVE-2006-6482
Description
Adobe ColdFusion MX7 allows remote attackers to obtain sensitive information via a URL request (1) for a non-existent (a) JWS, (b) CFM, (c) CFML, or (d) CFC file, which displays the installation path in the resulting error message; or (2) to /CFIDE/administrator/login.cfm without a host, which can reveal the server's internal IP address in an HREF tag.
Affected products
2- cpe:2.3:a:adobe:coldfusion:7.0:*:*:*:*:*:*:*
- Range: = MX7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- securitytracker.com/idnvdVendor Advisory
- secunia.com/advisories/23281nvd
- securityreason.com/securityalert/2021nvd
- www.securityfocus.com/archive/1/454046/100/0/threadednvd
- www.securityfocus.com/bid/21532nvd
- www.vupen.com/english/advisories/2006/4949nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/30839nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/30840nvd
News mentions
0No linked articles in our index yet.