Adobe Releases Fix for Critical ColdFusion Vulnerability
Adobe has released a patch for an exploitable vulnerability affecting ColdFusion, Adobe’s commercial Rapid Application Development platform. ColdFusion web sites may become compromised because there is a vulnerability in FCKEditor that a person with malicious intent can exploit; and according to the California-based company that specializes in creating multimedia and creativity software products that is precisely what is happening – the vulnerability is being actively exploited.
“A vulnerability in FCKEditor, which is included as part of ColdFusion 8, could allow a remote attacker to upload files in arbitrary directories which could lead to a system compromise. This issue is remotely exploitable. There are reports that this issue is being exploited in the wild,” explains the security bulletin that Adobe released in response to the ColdFusion vulnerability report.
The following software versions are affected by this vulnerability: ColdFusion 8 and ColdFusion 8.0.1. Adobe advises that all affected ColdFusion customers update to ColdFusion 8.0.1 and then apply the hot fix the company released. This process includes a few simple steps, detailed below:
1. First of all update to ColdFusion 8.0.1, then download and unzip the hot fix.
2. Open the ColdFusion Administrator and using the System Information page, apply the hot fix.
3. Backup the /CFIDE/scripts/ajax/FCKeditor folder. Do this outside the webroot.
4. Download this CFIDE.zip file and unzip it. Merge this CFIDE folder with the CFIDE already in place in the webroot. When prompted, overwrite the files in the existing CFIDE folder.
5. Delete these files: cf5_upload.cfm and cf5_connector.cfm. You will find them in cfwebroot\CFIDE\scripts\ajax\FCKeditor\editor\filemanager\connectors\cfm
6. Restart ColdFusion.
“A vulnerability in FCKEditor, which is included as part of ColdFusion 8, could allow a remote attacker to upload files in arbitrary directories which could lead to a system compromise. This hotfix updates the version of FCKEditor included with ColdFusion 8, turns off file upload capabilities by default, restricts access to cfm files in the FCKeditor\editor\filenamanger directory, and limits file upload capabilities to users with valid sessions. This issue is remotely exploitable. There are reports that this issue is being exploited in the wild,” added Adobe.
Tags: Adobe, ColdFusion, Security, Vulnerability
“A vulnerability in FCKEditor, which is included as part of ColdFusion 8, could allow a remote attacker to upload files in arbitrary directories which could lead to a system compromise. This issue is remotely exploitable. There are reports that this issue is being exploited in the wild,” explains the security bulletin that Adobe released in response to the ColdFusion vulnerability report.
Advertising
The following software versions are affected by this vulnerability: ColdFusion 8 and ColdFusion 8.0.1. Adobe advises that all affected ColdFusion customers update to ColdFusion 8.0.1 and then apply the hot fix the company released. This process includes a few simple steps, detailed below:
1. First of all update to ColdFusion 8.0.1, then download and unzip the hot fix.
2. Open the ColdFusion Administrator and using the System Information page, apply the hot fix.
3. Backup the /CFIDE/scripts/ajax/FCKeditor folder. Do this outside the webroot.
4. Download this CFIDE.zip file and unzip it. Merge this CFIDE folder with the CFIDE already in place in the webroot. When prompted, overwrite the files in the existing CFIDE folder.
5. Delete these files: cf5_upload.cfm and cf5_connector.cfm. You will find them in cfwebroot\CFIDE\scripts\ajax\FCKeditor\editor\filemanager\connectors\cfm
6. Restart ColdFusion.
“A vulnerability in FCKEditor, which is included as part of ColdFusion 8, could allow a remote attacker to upload files in arbitrary directories which could lead to a system compromise. This hotfix updates the version of FCKEditor included with ColdFusion 8, turns off file upload capabilities by default, restricts access to cfm files in the FCKeditor\editor\filenamanger directory, and limits file upload capabilities to users with valid sessions. This issue is remotely exploitable. There are reports that this issue is being exploited in the wild,” added Adobe.
Tags: Adobe, ColdFusion, Security, Vulnerability
I Hope you LIKE this blog post! Thank you!
What do YOU have to say about this
blog comments powered by Disqus
Popular News
By George Norman on 09 Feb 2012
Redmond-based software giant Microsoft is giving all US residents the chance to win a Pink Sony VAIO Y laptop (ARV $6,000) as part of a Valentine’s Day SweepstakesBy George Norman on 09 Feb 2012
The latest stable version of Google Chrome web browser is v. 17.0 which was rolled out to the public on Wednesday, the 8th of February, one day after the release of Chrome for Android Beta 1Related News
By George Norman on 09 Sep 2011
Adobe, California-based company that specializes in creating multimedia and creativity software products supports its products for a time period of five years. The company announced yesterdayBy George Norman on 05 Jan 2012
This is proof that there are a lot of threats on the web and the perfect example of why you should use a properly good security solution to secure your data against viruses and other malwareBy George Norman on 17 Nov 2011
We all know that the internet is a dangerous place. There are all sorts of nasties out there, from viruses and worms to scammers and cyber criminals. As a parent, it is your task to make sure that your children stay safe online. This means you have toBy George Norman on 28 Nov 2011
Back in August we were reporting that Avast has a grand total of 160 million registered Avast! Free Antivirus Users. Fabricia from Brazil, the 160 millionth user to register the free antivirus product was rewarded withAdvertising
Hot Software Updates
Top Downloads
2.
Opera5.
Trillian8.
AIM9.
Skype10.
Ad-Aware12.
Nero13.
Google Earth14.
Picasa15.
Winamp16.
iTunes17.
RealPlayer18.
uTorrent19.
eMule20.
WinRAR21.
BitComet22.
WinZip23.
Shareaza24.
CCleaner25.
Recuva26.
Tweak UI27.
CuteFTP Home29.
Adobe Reader30.
NewsPiperBecome A Fan!
Link To Us!
Adobe Releases Fix for Critical ColdFusion Vulnerability
HTML Linking Code
HTML Linking Code





