PT-2005-2045 · Adobe · Coldfusion
Sean Waddell
·
Published
2005-04-09
·
Updated
2016-10-18
·
CVE-2005-1022
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ColdFusion version 6.1
Description
The issue allows remote attackers to obtain sensitive information because Java .class files are placed under the web root in the /WEB-INF/cfclasses directory.
Recommendations
For ColdFusion version 6.1, consider restricting access to the /WEB-INF/cfclasses directory to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coldfusion