CVE-2003-1469 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 6.2% (pctl 93)
Patch early
A public exploit exists.
Description
The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error message.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| EPSS | 6.19% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-12-31 |
| Last modified | 2026-06-16 |
Affected (5)
| Vendor | Product |
|---|---|
| macromedia | coldfusion |
| macromedia | coldfusion professional |
| microsoft | windows 2000 |
| microsoft | windows nt |
| microsoft | windows xp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Macromedia ColdFusion MX 6.0 - Error Message Full Path Disclosure | 2003-04-26 |
References
- http://securityreason.com/securityalert/3307
- http://www.nii.co.in/vuln/pdmac.html
- http://www.securityfocus.com/archive/1/319867
- http://www.securityfocus.com/bid/7443
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11879
- http://securityreason.com/securityalert/3307
- http://www.nii.co.in/vuln/pdmac.html
- http://www.securityfocus.com/archive/1/319867
- http://www.securityfocus.com/bid/7443
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11879
→ the Explorer · watch your stack · NVD