Short Name |
SCAN:MISC:HTTP:EXAMPLEAPP-PRB |
---|---|
Severity |
Info |
Recommended |
No |
Category |
SCAN |
Keywords |
Coldfusion Exampleapp Probe |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects access to the exampleapp application that ships by default with some versions of ColdFusion. Attackers can use this application to gain control of a Web server.
Allaire Macromedia ColdFusion is a web application server. It supports quick development, publication and management of web content. By design, sample applications do not permit access from any other source than the ColdFusion server itself. A flaw exists in two sample applications which could enable a remote user to bypass this feature. Allowing the user to take any desired action including creating files, viewing files, or executing arbitrary commands on the target host.