Path Disclosure Vulnerability in Macromedia ColdFusion MX Server

Reported April 26, 2003, by Network Intelligence India Pvt. Ltd.

 

 

VERSIONS AFFECTED

 

  • Macromedia’s ColdFusion MX Server

 

DESCRIPTION

 

A vulnerability in Macromedia Coldfusion MX Server’s default installation can result in the inadvertent disclosure of the physical path of the server installation. A malicious user can connect to the vulnerable host on port 8500 (e.g., http://localhost:8500/CFIDE/probe.cfm) and issue an invalid request. The software returns an error message that displays the physical path:

Error occurred in:

C:\CFusionMX\wwwroot\CFIDE\probe.cfm:line56

 

VENDOR RESPONSE

 

In a default installation, the Enable Robust Exception Information setting is enabled under Debugging Settings. According to Macromedia, this setting should be cleared on production systems.

 

CREDIT

 

Discovered by Network Intelligence India Pvt. Ltd.

Please or Register to post comments.

Upcoming Training

Mastering System Center 2012

During over 6 hours of training you can join John Savill from your computer as he will walk you through the key components and capabilities of System Center 2012, what’s involved in using the components, and the benefit they can bring to your environment.

Register Now

Current Issue

May 2013 - The NameTranslate object is useful when you need to translate Active Directory object names between different formats, but it's awkward to use from PowerShell. Here's a PowerShell script that eliminates the awkwardness.

CURRENT ISSUE / ARCHIVE / SUBSCRIBE

Windows Forums

Get answers to questions, share tips, and engage with the Windows Community in our Forums.