Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ColdFusion Sample Application Command Execution Vulnerability

Allaire Macromedia ColdFusion is a web application server. It supports quick development, publication and management of web content.

By design, sample applications do not permit access from any other source than the ColdFusion server itself. A flaw exists in two sample applications which could enable a remote user to bypass this feature. Allowing the user to take any desired action including creating files, viewing files, or executing arbitrary commands on the target host.







 

Privacy Statement
Copyright 2008, SecurityFocus