Description
Directory traversal vulnerability in Adobe ColdFusion 9.0.1 and earlier allows attackers to obtain sensitive information. The vulnerability is a variation of a classic directory traversal vulnerability, also referred to as 'arbitrary file retrieval'. The attack involves tricking a server-side script to provide the contents of a file that it was not originally supposed to be made available. By 'moving up' a few directory levels, the attacker is able to obtain the contents of files outside the application server's webroot via special strings such as '../'.
Remediation
Apply the fix provided by Adobe. Check Web References.
References
Security update: Hotfix available for ColdFusion
Vulnerability Summary for CVE-2010-2861
Related Vulnerabilities
Oracle HTTP Server CVE-2020-2530 Vulnerability (CVE-2020-2530)
WordPress Plugin Widget Control Powered By Everyblock Cross-Site Scripting (1.0.1)
MySQL CVE-2024-20981 Vulnerability (CVE-2024-20981)
WordPress Plugin BackWPup Cross-Site Scripting (3.2.3)
Joomla URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-23798)