vendor:
ColdFusion
by:
Matt Chapman
4,3
CVSS
MEDIUM
Decryption of ColdFusion encrypted templates
N/A
CWE
Product Name: ColdFusion
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Decrypt Cold Fusion templates encrypted with CFCRYPT
A vulnerability in ColdFusion allows pages encrypted with the CFCRYPT.EXE utility to be decrypted. A program that decrypts ColdFusion's encryption has been discovered, making the source code for all propietary CFML applications available to those with access to their encrypted form.
Mitigation:
Ensure that all ColdFusion templates are encrypted with the CFCRYPT.EXE utility.