ColdFusion 5.0 and earlier on Windows systems allows remote attackers to determine the absolute pathname of .cfm or .dbm files via an HTTP request that contains an MS-DOS device name such as NUL, which leaks the pathname in an error message.
| Software | From | Fixed in |
|---|---|---|
| allaire / coldfusion_server | 5.0 | 5.0.x |
| allaire / coldfusion_server | 4.0 | 4.0.x |
| allaire / coldfusion_server | 4.5 | 4.5.x |