HTTP: Coldfusion cfcache.map Info Disclosure

This signature detects access to the cfcache.map files. Attackers can access potentially dangerous Web server information.

Extended Description

ColdFusion 4.x includes a function called CFCACHE. This function improves server performance by caching the HTML output of processed CFM pages. When the CFCACHE tag is used in a CFM page, it creates temporary files. Some of these files are .tmp files, which contain the actual HTML output. It also creates a cfcache.map file, which contains pointers to the .tmp files including absolute pathnames, timestamps, and other URL information. This information could be potentially harmful if exposed to the public. These files are all placed in the same web-accessible directory as the CFM file itself, and can be remotely accessed via an explicit URL.

Affected Products

Allaire coldfusion_server

References

BugTraq: 917

CVE: CVE-2000-0057

Short Name
HTTP:COLDFUSION:CFCACHE-MAP
Severity
Warning
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2000-0057 Coldfusion Disclosure Info bid:917 cfcache.map
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Allaire

CVSS Score

7.5

Found a potential security threat?