ColdFusion CFReThrow Tag Denial Of...

- AV AC AU C I A
发布: 2001-07-30
修订: 2025-04-13

ColdFusion is a Web Application software packaged distributed and maintained by Allaire. The CFRETHROW tag causes a crash in the ColdFusion server when it's use is attempted on a ColdFusion/Linux server combination. Upon receipt of the tag, ColdFusion crashes creating a core file in the coldfusion/logs subdirectory of the ColdFusion installation directory. This problem allows a user to crash a ColdFusion server, and potentially gain access to sensitive information about the server.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息