CVE

Id
13687  
CVE No.
CVE-2005-2481  
Status
Candidate  
Description
ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the "?" (question mark) character.  
Phase
Assigned (20050805)  
Votes
None (candidate not yet proposed)  
Comments