ColdFusion CFReThrow Tag Denial Of Service Vulnerability
BID:3126
Info
ColdFusion CFReThrow Tag Denial Of Service Vulnerability
| Bugtraq ID: | 3126 |
| Class: | Environment Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 30 2001 12:00AM |
| Updated: | Jul 30 2001 12:00AM |
| Credit: | This vulnerability was posted to Bugtraq by Eric Lackey <[email protected]> on July 30, 2001. |
| Vulnerable: |
Allaire ColdFusion Server 5.0 Allaire ColdFusion Server 4.5.1 |
| Not Vulnerable: | |
Discussion
ColdFusion CFReThrow Tag Denial Of Service Vulnerability
ColdFusion is a Web Application software packaged distributed and maintained by Allaire.
The CFRETHROW tag causes a crash in the ColdFusion server when it's use is attempted on a ColdFusion/Linux server combination. Upon receipt of the tag, ColdFusion crashes creating a core file in the coldfusion/logs subdirectory of the ColdFusion installation directory.
This problem allows a user to crash a ColdFusion server, and potentially gain access to sensitive information about the server.
ColdFusion is a Web Application software packaged distributed and maintained by Allaire.
The CFRETHROW tag causes a crash in the ColdFusion server when it's use is attempted on a ColdFusion/Linux server combination. Upon receipt of the tag, ColdFusion crashes creating a core file in the coldfusion/logs subdirectory of the ColdFusion installation directory.
This problem allows a user to crash a ColdFusion server, and potentially gain access to sensitive information about the server.
Exploit / POC
ColdFusion CFReThrow Tag Denial Of Service Vulnerability
See discussion.
See discussion.
Solution / Fix
ColdFusion CFReThrow Tag Denial Of Service Vulnerability