|
|
|
|
|
|
|
| |
ColdFusion Debug Mode Information Disclosure |
|
| This script is Copyright (C) 2001-2010 Felix Huber |
|
|
| Family | CGI abuses |
| Nessus Plugin ID | 10797 (cf_debug.nasl) |
| Bugtraq ID |
|
| CVE ID |
|
|
| Description: |
Synopsis :
The remote web server is hosting a CGI application that is affected
by an information disclosure vulnerability.
Description :
It is possible to see the ColdFusion Debug Information by appending
'?Mode=debug' at the end of the request.
ColdFusion 4.5 and 5.0 are definitely concerned (probably in
addition older versions).
The Debug Information usually contain sensitive data such
as Template Path or Server Version.
See also :
http://www.adobe.com/products/coldfusion/?promoid=home_prod_cf_082403
Solution :
Enter an IP (e.g. 127.0.0.1) in the Debug Settings within the
ColdFusion Admin.
Risk factor :
Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
|
|
|
|
|
|