Skip navigation

Path Disclosure Vulnerability in Macromedia ColdFusion MX Server

Reported April 26, 2003, by Network Intelligence India Pvt. Ltd.

 

 

VERSIONS AFFECTED

 

  • Macromedia’s ColdFusion MX Server

 

DESCRIPTION

 

A vulnerability in Macromedia Coldfusion MX Server’s default installation can result in the inadvertent disclosure of the physical path of the server installation. A malicious user can connect to the vulnerable host on port 8500 (e.g., http://localhost:8500/CFIDE/probe.cfm) and issue an invalid request. The software returns an error message that displays the physical path:

Error occurred in:

C:\CFusionMX\wwwroot\CFIDE\probe.cfm:line56

 

VENDOR RESPONSE

 

In a default installation, the Enable Robust Exception Information setting is enabled under Debugging Settings. According to Macromedia, this setting should be cleared on production systems.

 

CREDIT

 

Discovered by Network Intelligence India Pvt. Ltd.

TAGS: Security
Hide comments

Comments

  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
Publish