Code (not sql) injection by hackers via coldfusion
Does anyone have any information on how hackers might inject code into my coldfusion files. I am having a problem with hackers installing javascript links to their trojans inside the actual pages of my site. I run the server with many different sites on it and the injections are ONLY happening on the coldfusion sites. I tried to search for code injection coldfusion information through the search engines and this forum but didn't find anything. What potential holes in my coldfusion code would allow a hacker to inject code into the actual files on the server? I am mainly seeing the code injected into application.cfm itself so that the links are displayed on every page. Guess these hackers are familiar with coldfusion.
