ColdFusion contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker specifies the OpenFilePath variable in the Expression Evaluator. This allows an attacker to view the contents of arbitrary files on the server and may result in a loss of confidentiality.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Workaround,
Patch / RCS,
Upgrade
Exploit:
Exploit Public
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Upgrade to version 4.0.1 or higher, as it has been reported to fix this vulnerability. Additionally, the vendor has released a patch for Windows NT and Solaris installation to address this issue, or users may opt to apply the following workaround: remove all sample code from the server.