← Volver a CVEs
CVE-2011-0736
MEDIUM5.3
Descripcion
Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database structure via an id=- query to a .cfm file. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure
Detalles CVE
Puntuacion CVSS v3.15.3
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado2/1/2011
Ultima modificacion4/29/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
adobe:coldfusion
Debilidades (CWE)
CWE-200
Referencias
http://osvdb.org/70780(cve@mitre.org)
http://websecurity.com.ua/4879/(cve@mitre.org)
http://archives.neohapsis.com/archives/fulldisclosure/2011-01/0537.html(af854a3a-2127-422b-91ae-364da2661108)
http://osvdb.org/70780(af854a3a-2127-422b-91ae-364da2661108)
http://websecurity.com.ua/4879/(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.