Adobe ColdFusion 8.0.1 and earlier might allow attackers to obtain sensitive information via unspecified vectors, related to a "double-encoded null character vulnerability."
https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1871
http://www.adobe.com/support/security/bulletins/apsb09-12.html