← Back

CVE-2005-2481

nvd nist
Published: Aug 5, 2005Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the "?" (question mark) character.

Affected (1)

1 product
Coldfusion Fusebox
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.1.0

References (2)

Timeline

No history available yet.