MEDIUM · 5.0

CVE-2004-0928

The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE allows remote attackers to bypass authentication and view source files, such as .asp, .pl, and .php files, v...

Vulnerability Description

The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE allows remote attackers to bypass authentication and view source files, such as .asp, .pl, and .php files, via an HTTP request that ends in ";.cfm".

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
HitachiCosminexus Enterprise01_01_1
HitachiCosminexus Serverweb_01-01_1
MacromediaColdfusion6.0
MacromediaJrun3.0

References

FAQ

What is CVE-2004-0928?

CVE-2004-0928 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE allows remote attackers to bypass authentication and view source files, such as .asp, .pl, and .php files, v...

How severe is CVE-2004-0928?

CVE-2004-0928 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0928?

Check the references section above for vendor advisories and patch information. Affected products include: Hitachi Cosminexus Enterprise, Hitachi Cosminexus Server, Macromedia Coldfusion, Macromedia Jrun.