Security Advisory
CVE-2005-1022
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
ColdFusion 6.1 Updater 1 places Java .class files under the web root in the /WEB-INF/cfclasses directory, which allows remote attackers to obtain sensitive information.