Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:COLDFUSION:CFCACHE-MAP

Severity

Low

Recommended

No

Category

HTTP

Keywords

Coldfusion cfcache.map Info Disclosure

Release Date

2003/04/22

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Coldfusion cfcache.map Info Disclosure


This signature detects access to the cfcache.map files. Attackers can access potentially dangerous Web server information.

Extended Description

ColdFusion 4.x includes a function called CFCACHE. This function improves server performance by caching the HTML output of processed CFM pages. When the CFCACHE tag is used in a CFM page, it creates temporary files. Some of these files are .tmp files, which contain the actual HTML output. It also creates a cfcache.map file, which contains pointers to the .tmp files including absolute pathnames, timestamps, and other URL information. This information could be potentially harmful if exposed to the public. These files are all placed in the same web-accessible directory as the CFM file itself, and can be remotely accessed via an explicit URL.

Affected Products

  • Allaire ColdFusion Server 4.0.0
  • Allaire ColdFusion Server 4.0.1

References

  • BugTraq: 917
  • CVE: CVE-2000-0057

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out