Description: Two vulnerabilities have been reported in ColdFusion, which can be exploited by malicious, local users to bypass certain security restrictions and by malicious people to cause a DoS (Denial of Service).
1) It is possible to cause an infinite loop in ColdFusion by sending a specially crafted command to the ColdFusion Flash Remoting Gateway.
2) An error exists due to CFML templates outside a sandbox being able to call ColdFusion components within a sandbox in certain situations.
The vulnerabilities have been reported in versions 7 and 7.0.1.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.