APP: Macromedia ColdFusion MX Path Disclosure

This signature detects attempts to access the fileprobe.cfm. With default settings, Macromedia ColdFusion MX will return an error message containing the full path of the ColdFusion software. Versions 6.x are vulnerable.

Extended Description

A vulnerability has been reported for Macromedia ColdFusion MX that may reveal the physical path information to attackers. When certain malformed URL requests are received by the server, an error message is returned containing the full path of the ColdFusion installation.

Affected Products

Macromedia coldfusion_server

Short Name
APP:COLDFUSIONMX-ACC
Severity
Info
Recommended
False
Recommended Action
None
Category
APP
Keywords
ColdFusion Disclosure MX Macromedia Path bid:7443
Release Date
08/03/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
Port
TCP/8500
False Positive
Rarely
Vendors

Macromedia

Found a potential security threat?