Tenable Nessus vulnerability scan on the ColdFusion cfcexplorer.cfc component--CF11
Using the GET HTTP method, Nessus found that the following resources may be vulnerable to blind SQL injection :
The 'method' parameter of the /CFIDE/componentutils/cfcexplorer.cfc CGI :
Input: /CFIDE/componentutils/cfcexplorer.cfc?path=%2fCFIDE%2fappdeployment%2fID atasourcesEventsHandler.cfc&name=CFIDE.appdeployment.IDatasourcesEventsH andler&method=getcfcinhtml'||'%2fCFIDE%2fappdeployment%2fIDatasourcesEve ntsHandler.cfc&name=CFIDE.appdeployment.IDatasourcesEventsHandler&method =getcfcinhtml
-------- output -------- HTTP/1.1 200 OK
-------- vs -------- HTTP/1.1 400 Bad Request ------------------------"
Is this vulnerabilty exists or it is a false positive?
