Great Reviews!Need help setting up your website, installing Apache, PHP, MySQL, or PhpNuke?Need help customizing or designing scripts?Please contact me via the Contact Us option for further details and pricing.
DESCRIPTION: Inge Henriksen has reported a vulnerability in Adobe ColdFusion MX, which can be exploited by malicious people to disclose potentially sensitive information.
The vulnerability is caused due to an input validation error when processing URL-encoded file names. This can be exploited to view arbitrary files on the web root via a specially crafted URL with a doubly-encoded NULL byte and an extension that is handled by ColdFusion e.g. ".cfm". The vulnerability is reported in version 7.0.2 running on Windows IIS. Other versions may also be affected.
SOLUTION: Apply hotfix (See vendor's advisory for details).
PROVIDED AND/OR DISCOVERED BY: Discovered by Inge Henriksen and reported via iDefense Labs.
ORIGINAL ADVISORY: Adobe: http://www.adobe.com/support/security/bulletins/apsb07-02.html