ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files.
| Software | From | Fixed in |
|---|---|---|
| allaire / coldfusion_server | 4.0 | 4.0.x |
| allaire / coldfusion_server | 4.0.1 | 4.0.1.x |
| allaire / coldfusion_server | 4.5 | 4.5.x |