Here is an interesting vulnerability that I have come across several times in real CFML code during code reviews, I have spoken about it at conferences but have never written about it. Since it doesn't really have a name, I call it Scope Injection, you'll see why in a minute.
We have the following code here........http://www.petefreitag.com/item/834.cfm
We have the following code here........http://www.petefreitag.com/item/834.cfm