Reported April 26, 2003, by Network Intelligence India Pvt. Ltd.
Macromedia’s ColdFusion MX Server
A vulnerability in Macromedia Coldfusion MX Server’s default installation can result in the inadvertent disclosure of the physical path of the server installation. A malicious user can connect to the vulnerable host on port 8500 (e.g., http://localhost:8500/CFIDE/probe.cfm) and issue an invalid request. The software returns an error message that displays the physical path:
Error occurred in:
In a default installation, the Enable Robust Exception Information setting is enabled under Debugging Settings. According to Macromedia, this setting should be cleared on production systems.
Discovered by Network Intelligence India Pvt. Ltd.