« Volver al listado

CVE-2011-0736

Estado: ModificadaMedia (5.3)—

Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database structure via an id=- query to a .cfm file. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-0736",
  "cveTags": [
    {
      "tags": [
        "disputed"
      ],
      "sourceIdentifier": "cve@mitre.org"
    }
  ],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2011-0736",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-21T17:41:49.462339Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-02-01T18:00:03.970",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2011-01/0537.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/70780",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://websecurity.com.ua/4879/",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2011-01/0537.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/70780",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://websecurity.com.ua/4879/",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database structure via an id=- query to a .cfm file.  NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure"
    },
    {
      "lang": "es",
      "value": "** DISPUTADA ** Adobe ColdFusion 9.0.1 CHF1 y anteriores, cunado una aplicación web está configurada para utilizar un DBMS, permite a atacantes remotos obtener información potencialmente sensible acerca de la estructura de la base de datos a través de una consulta id=- a un fichero .cfm. NOTA: El proveedor disputa la importancia de este problema porque las secciones Site-wide Error Handler y Debug Output Settings de la guía ColdFusion Lockdown explican el requisito para las configuraciones que previenen esta divulgación de información."
    }
  ],
  "lastModified": "2026-06-16T23:27:58.780",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:*:chf1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C855D9BA-832F-4C79-90D6-4268DA717922",
              "versionEndIncluding": "9.0.1"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:4.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D37C9E4-CDFC-450B-AEE8-DB204AFB7030"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "91CF7A97-1D87-44B7-804E-17E4037FC763"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73DAF349-B29C-44D0-818B-8D665D2B35EC"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "720437A6-66D3-4DD6-A40F-23FC107AD710"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31D67D32-16BD-437C-8423-4704364EE737"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:7.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C1CF5F6-BA6A-4EAC-8E94-238E0B9C64B5"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:7.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B015715F-9672-480E-B0AA-968D8C9070D5"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD6C1877-7412-4FBE-9641-334971F9D153"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:8.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "28C8D6AF-EDE1-42BD-A47C-2EF8690299BD"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "810E1B9C-E32F-4788-8705-67F855DC9EE6"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "113431FB-E4BE-4416-800C-6B13AD1C0E92"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:9.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7FBC38B4-D957-4645-BA96-E99975271482"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}