
• Information Disclosure
• Need to determine standard vs Enterprise
ColdFusion? *
• Just request a .jsp page
– Standard versions don’t do JSP and will tell
you so via 500 error && license exception
– Enterprise supports jsp and will just 404
• *useful for post exploitation
Attacking ColdFusion
Comentarios a estos manuales