1. Security flaw in leaking that much error info. 2. Who uses ColdFusion in 2013?
1. Security flaw in leaking that much error info. 2. Who uses ColdFusion in 2013?
Not that I disagree with you, but I wonder if the reasons you have in mind are valid. A lot of the reasons one might assume CF sucks aren't really applicable (i.e. speed, security) any more than most other languages.
If it works, and you can maintain it - its all good. Even Cold Fusion, even PHP, even Perl, even Brainf#@k
The consequences come for the poor bastards that have that old crap on their resume... Bus number notwithstanding...
Just like Coldfusion, many people have been saying Java is so 1995 but since Twitter showed how well Java scales compared to the woeful RoR it is seeing a renaissance. And since Railo is a Java framework that speeds development I have a feeling we will being seeing it experience a similar renaissance in the near future.
I agree that the owner of the website here needs a <CFERROR> tag, which tells the server what to do instead of showing that big error message.
the issue seems coming from this line:
https://github.com/cfwheels/cfwheels/blob/v1.1.8/wheels/even...
basically when wheels throws an error, it will try to send out an error email containing the environment and framework information. In this case there seems to be no smtp server defined, so CFML itself is spitting up its skull.
The error handling can be reworked so that the $mail() call is wrap in a try/catch so the 500 page will just be shown.
disclosure: part of wheels core.
Me? Because I have to maintain a rather old site for my employer, and there is absolutely no chance that anyone would sign-off on migrating it to a different platform.
Interestingly, about a year ago, we were told that we would no longer be doing any updates to the system, and yet, here we are, a year later, still doing minor releases. I suspect it will never go away.
WRT to open source: in open source software, you theoretically have many benign eyes vetting your code for security issues, whereas with closed source applications, the only people who are looking for security holes are you and attackers. :)
https://www.google.com/search?q=releaseDetail.cfm
Its not the sexiest of platforms out there, but it can get the job done...
[1] - http://webpulp.tv/episodes/managing-8-petabytes-and-virtual-... [2] - https://blog.linode.com/2013/04/16/security-incident-update/
About 2/3 of the federal government.
Also, that isn't ColdFusion, it's Railo, an OS alternative.