← Back to CVEs
CVE-2011-0736
MEDIUM5.3
Description
Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database structure via an id=- query to a .cfm file. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure
CVE Details
CVSS v3.1 Score5.3
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published2/1/2011
Last Modified4/29/2026
Sourcenvd
Honeypot Sightings0
Affected Products
adobe:coldfusion
Weaknesses (CWE)
CWE-200
References
http://osvdb.org/70780(cve@mitre.org)
http://websecurity.com.ua/4879/(cve@mitre.org)
http://archives.neohapsis.com/archives/fulldisclosure/2011-01/0537.html(af854a3a-2127-422b-91ae-364da2661108)
http://osvdb.org/70780(af854a3a-2127-422b-91ae-364da2661108)
http://websecurity.com.ua/4879/(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.