Status/Resolution/Reason: Closed/Fixed/Fixed
Reporter/Name(from Bugbase): Bradley Wood / ()
Created: 07/11/2018
Components: Debugging
Versions: 2016,2018
Failure Type: Others
Found In Build/Fixed In Build: Final / latest
Priority/Frequency: Critical /
Locale/System: / Platforms All
Vote Count: 2
In 2016 we were told that we could block CFIDE from public access and all static assets could be controlled from the cf scripts default directory which was configurable. However, when you chose the "dockable.cfm" debugging output setting, there are requests to images such as:
http://servername/CFIDE/debug/images/bgleft.gif
These appear to be hard coded to point to CFIDE and don't obey the scripts setting. This means that there is no way for these images to work on a server that's had the CFIDE folder properly locked down.
Attachments:
Comments: