http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
--------- 05:43 < ryan||> Well linode also had terribly configured coldfusion
05:57 < ryann> <cfif ListLen(cgi.script_name, "/") gt 2 AND ListGetAt(cgi.script_name, 2, "/") eq "linode" AND NOT ListFind("index.cfm,linode_edit.cfm,linode_resize.cfm,label.cfm,cancel.cfm,dc_choose.cfm,su.cfm,pastdue.cfm", ListGetAt(cgi.script_name, 3, "/"))> <cfinclude template="/members/linode/common/dsp_topNav.cfm"> </cfif>
05:57 < ryann> this code
05:57 < ryann> It's so dirty I feel bad reading it
Also if you check out my reply below I've C&P'ed the chat logs where he claims it is a zero day:
https://news.ycombinator.com/item?id=5552992
Plus another commenter has linked to a security advisory for exploits in CF that was issued a few days ago.
http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
--------- 05:43 < ryan||> Well linode also had terribly configured coldfusion
05:57 < ryann> <cfif ListLen(cgi.script_name, "/") gt 2 AND ListGetAt(cgi.script_name, 2, "/") eq "linode" AND NOT ListFind("index.cfm,linode_edit.cfm,linode_resize.cfm,label.cfm,cancel.cfm,dc_choose.cfm,su.cfm,pastdue.cfm", ListGetAt(cgi.script_name, 3, "/"))> <cfinclude template="/members/linode/common/dsp_topNav.cfm"> </cfif>
05:57 < ryann> this code
05:57 < ryann> It's so dirty I feel bad reading it