|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
ColdFusion contains a flaw that allows a remote attacker to read any file on the system. The flaw is due to poor sanity checking on arguments passed to the sourcewindow.cfm script, which is installed by default.
|
|
Classification |
Unknown or Incomplete
|
|
Solution |
Users of ColdFusion 4.0 should upgrade or patch to version 4.0.1 or higher, as it has been reported to fix this vulnerability. Users of ColdFusion 2.x or 3.x should remove all sample applications, as the 4.0.1 patch does not apply to your installations.
|
|
Products |
|
ColdFusion
 |
4.0 |
2.x |
3.x |
|
|
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|