Allaire ColdFusion Path Disclosure Vulnerability
BID:1021
Info
Allaire ColdFusion Path Disclosure Vulnerability
| Bugtraq ID: | 1021 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Mar 01 2000 12:00AM |
| Updated: | Mar 01 2000 12:00AM |
| Credit: | Posted to NTBugtraq by vwaaijen <[email protected]> on March 1, 2000. |
| Vulnerable: |
Allaire ColdFusion Server 4.5 Allaire ColdFusion Server 4.0.1 Allaire ColdFusion Server 4.0 |
| Not Vulnerable: |
Allaire ColdFusion Server 4.5.1 |
Discussion
Allaire ColdFusion Path Disclosure Vulnerability
Making an http request directly to an existing APPLICATION.CFM or ONREQUESTEND.CFM file will return an error message containing the full physical path to the file.
Making an http request directly to an existing APPLICATION.CFM or ONREQUESTEND.CFM file will return an error message containing the full physical path to the file.
Exploit / POC
Allaire ColdFusion Path Disclosure Vulnerability
http://target/application.cfm
http://target/application.cfm
Solution / Fix
Allaire ColdFusion Path Disclosure Vulnerability
Solution:
Allaire is aware of the issue and it is fixed as of the 4.5.1 release.
Upgrades are available from:
http://www.allaire.com/developer/securityzone/
Solution:
Allaire is aware of the issue and it is fixed as of the 4.5.1 release.
Upgrades are available from:
http://www.allaire.com/developer/securityzone/
References
Allaire ColdFusion Path Disclosure Vulnerability
References:
References: