vendor:
ColdFusion
by:
Matt Chapman
4.3
CVSS
MEDIUM
Decryption Vulnerability
326
CWE
Product Name: ColdFusion
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
ColdFusion CFCRYPT.EXE Decryption Vulnerability
A vulnerability in ColdFusion allows pages encrypted with the CFCRYPT.EXE utility to be decrypted. A program that decrypts ColdFusion's encryption has been discovered. This will in effect make the source code for all this propietary CFML applications available to those with access to their encrypted form.
Mitigation:
Ensure that the encryption key is kept secure and not accessible to unauthorized users.