>> Adobe ColdFusion MX Encoded Filenames Handling Information Disclosure Vulnerability
Title : Adobe ColdFusion MX Encoded Filenames Handling Information Disclosure Vulnerability VUPEN ID : VUPEN/ADV-2007-0116 CVE ID : CVE-2006-5858
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-10
Technical Description
A vulnerability has been identified in Adobe ColdFusion MX, which could be exploited by attackers to gain knowledge of sensitive information. This issue is due to an input validation when processing URLs containing a double encoded NULL byte and a valid extension (e.g. ".cfm"), which could be exploited by remote attackers to disclose the contents of arbitrary files on a vulnerable server.