ColdFusion 6.1 Updater 1 places Java .class files under the web root in the /WEB-INF/cfclasses directory, which allows remote attackers to obtain sensitive information.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-1025
http://www.macromedia.com/devnet/security/security_zone/mpsb05-02.html