The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE allows remote attackers to bypass authentication and view source files, such as .asp, .pl, and .php files, via an HTTP request that ends in ";.cfm".
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=109621995623823&w=2 | mailing list |
http://secunia.com/advisories/12647/ | third party advisory patch vendor advisory |
http://www.kb.cert.org/vuls/id/977440 | us government resource third party advisory patch |
http://www.idefense.com/application/poi/display?id=148&type=vulnerabilities | third party advisory patch vendor advisory |
http://www.securityfocus.com/bid/11245 | vdb entry patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17484 | vdb entry |
http://www.macromedia.com/devnet/security/security_zone/mpsb04-08.html | patch vendor advisory |
http://secunia.com/advisories/12638/ | third party advisory patch vendor advisory |
http://www.macromedia.com/devnet/security/security_zone/mpsb04-09.html | patch vendor advisory |