WEB_COLDFUSION getfile.cfm access

 

Code: p1035

Severity: Notice

 

Description: This event is generated when an attempt is made to access an Example application on a Coldfusion 4.x server.

Impact: Serious. The vulnerability is not limited to files in the webspace, so system files or additional unexecuted code files could be retrieved and examined for vulnerabilities.

Corrective: Delete all example code. This is one of several significant vulnerabilities that are exploitable if the example code is left on a production server.