peter bassill · operator
$ cve CVE-2003-1469 JSON

CVE-2003-1469 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 6.2% (pctl 93)

Patch early

A public exploit exists.

Description

The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error message.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS6.19% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2003-12-31
Last modified2026-06-16

Affected (5)

VendorProduct
macromediacoldfusion
macromediacoldfusion professional
microsoftwindows 2000
microsoftwindows nt
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD