Description
Directory traversal vulnerability in Adobe ColdFusion 9.0.1 and earlier allows attackers to obtain sensitive information. The vulnerability is a variation of a classic directory traversal vulnerability, also referred to as 'arbitrary file retrieval'. The attack involves tricking a server-side script to provide the contents of a file that it was not originally supposed to be made available. By 'moving up' a few directory levels, the attacker is able to obtain the contents of files outside the application server's webroot via special strings such as '../'.
Remediation
Apply the fix provided by Adobe. Check Web References.
References
Security update: Hotfix available for ColdFusion
Vulnerability Summary for CVE-2010-2861
Related Vulnerabilities
Atlassian Jira CVE-2020-36235 Vulnerability (CVE-2020-36235)
LimeSurvey Improper Restriction of XML External Entity Reference Vulnerability (CVE-2019-16174)
Oracle Database Server Other Vulnerability (CVE-2001-0943)
PHP NULL Pointer Dereference Vulnerability (CVE-2018-19935)
LimeSurvey Incorrect Default Permissions Vulnerability (CVE-2019-16186)