Added on 09 Jul 2009(407 Views)
Adobe has released a patch for an exploitable vulnerability affecting ColdFusion, Adobe’s commercial Rapid Application Development platform. ColdFusion web sites may become compromised because there is a vulnerability in FCKEditor that a person with malicious intent can exploit; and according to the California-based company that specializes in creating multimedia and creativity software products that is precisely what is happening – the vulnerability is being actively exploited.“A vulnerability in FCKEditor, which is included as part of ColdFusion 8, could allow a remote attacker to upload files in arbitrary directories which could lead to a system compromise. This issue is remotely exploitable. There are reports that this issue is being exploited in the wild,” explains the security bulletin that Adobe released in response to the ColdFusion vulnerability report.
The following software versions are affected by this vulnerability: ColdFusion 8 and ColdFusion 8.0.1. Adobe advises that all affected ColdFusion customers update to ColdFusion 8.0.1 and then apply the hot fix the company released. This process includes a few simple steps, detailed below:
1. First of all update to ColdFusion 8.0.1, then download and unzip the hot fix.
2. Open the ColdFusion Administrator and using the System Information page, apply the hot fix.
3. Backup the /CFIDE/scripts/ajax/FCKeditor folder. Do this outside the webroot.
4. Download this CFIDE.zip file and unzip it. Merge this CFIDE folder with the CFIDE already in place in the webroot. When prompted, overwrite the files in the existing CFIDE folder.
5. Delete these files: cf5_upload.cfm and cf5_connector.cfm. You will find them in cfwebroot\CFIDE\scripts\ajax\FCKeditor\editor\filemanager\connectors\cfm
6. Restart ColdFusion.
“A vulnerability in FCKEditor, which is included as part of ColdFusion 8, could allow a remote attacker to upload files in arbitrary directories which could lead to a system compromise. This hotfix updates the version of FCKEditor included with ColdFusion 8, turns off file upload capabilities by default, restricts access to cfm files in the FCKeditor\editor\filenamanger directory, and limits file upload capabilities to users with valid sessions. This issue is remotely exploitable. There are reports that this issue is being exploited in the wild,” added Adobe.
Don't forget to:
RSSTags: Adobe, ColdFusion, Security, Vulnerability
Link to this article:
Add comment:
Software News
Fun Friday Feature: Cry Translator iPhone App
I remember that some obscure school teacher once told me that speech separates man from beast. Now I always found that reasoning to be somewhat flawed. What about parrots? They can speak – sort of. Or...
06 Nov 2009
Chrome 3.0 and 4.0 Updated on the Stable and Dev Channel
The guys over at Google are keeping as busy, of not more so, as the guys over at Mozilla. While the Mozilla Foundation has recently released Firefox 3.6 Beta 1 and Firefox 3.5.5, Mountain View-based search engine giant Google ...
06 Nov 2009
November 09 Patch Tuesday: 6 Security Bulletins, 15 Vulnerabilities
Next week’s first two days are already booked. On Monday, the 9th of November, we will be celebrating Firefox’s 5th anniversary. On Tuesday, we will focus on something less entertaining, mainly patching our...
06 Nov 2009
Firefox 3.5.5 Update Released
The Mozilla Foundation has released another update for its browser, mainly Firefox 3.5.5. The update follows in the footsteps of Firefox 3.5.4, an update that was released about a week back...
06 Nov 2009
iTunes 9.0.2 Update Loves Apple TV 3.0 Software, Breaks Palm Pre Syncing (Again)
Cupertino-based software developer Apple has recently updated its digital media player iTunes to version 9.0.2. The update, which follows in the footsteps of iTunes 9.0.1 and iTunes 9.0, brings forth one significant new change...
05 Nov 2009
Blacksn0w: Unlock Tool for the iPhone 3G and 3GS
Great news for iPhone 3G and iPhone 3GS users that updated the device to baseband version 05.11; or iPhone 3G and iPhone 3GS users that bought the device with an updated baseband. Original iPhone hacker...
05 Nov 2009
Recommended Tools
Registry Booster 2009
Clean, Repair and Optimize your PC with the #1 industry leading and award-winning utility
Clean, Repair and Optimize your PC with the #1 industry leading and award-winning utility
Driver Scanner 2009
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
SpeedUpMyPC 2009
How fast is your PC really running? Turbo-charge your Internet and PC performance here
How fast is your PC really running? Turbo-charge your Internet and PC performance here



