ColdFusion 6.1 Updater 1 places Java .class files under the web root in the /WEB-INF/cfclasses directory, which allows remote attackers to obtain sensitive information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Coldfusion | Macromedia | 6.1 (including) | 6.1 (including) |