Path Disclosure Vulnerability in Macromedia ColdFusion MX Server

A vulnerability in Macromedia Coldfusion MX Server’s default installation can result in the inadvertent disclosure of the physical path of the server installation.

Ken Pfeil

April 29, 2003

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported April 26, 2003, by Network Intelligence India Pvt. Ltd.

 

 

VERSIONS AFFECTED

 

  • Macromedia’s ColdFusion MX Server

 

DESCRIPTION

 

A vulnerability in Macromedia Coldfusion MX Server’s default installation can result in the inadvertent disclosure of the physical path of the server installation. A malicious user can connect to the vulnerable host on port 8500 (e.g.,http://localhost:8500/CFIDE/probe.cfm) and issue an invalid request. The software returns an error message that displays the physical path:

Error occurred in:

C:CFusionMXwwwrootCFIDEprobe.cfm:line56

 

VENDOR RESPONSE

 

In a default installation, the Enable Robust Exception Information setting is enabled under Debugging Settings. According to Macromedia, this setting should be cleared on production systems.

 

CREDIT

 

Discovered byNetwork Intelligence India Pvt. Ltd.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like