security of coldfusion

Hello,

We got a support ticket from our client, and he write, that on coldfusion server from jodohost is not so strict security.

For example, he was able to list all files on server, include c: , e: throw cfdirectory action=list
he didn’t try to edit it or delete, but maybe it is also possible? ?(

Maybe we should enable Sandbox security and after give pathes for each users?

P.S. It is just copy from ticket :slight_smile: Me personally not guru of coldfusion and I would like to know opinion of othere clients.