Potential ColdFusion security issue

Adobe is aware of reports of ColdFusion websites being compromised through a vulnerability in the FCKEditor rich text editor, which is installed with ColdFusion 8. Adobe is working on an update to ColdFusion to resolve the issue, which we expect to make available next week. In the meantime, ColdFusion 8 administrators are advised to mitigate this issue by following the steps below:

1. Disable connectors by setting config.Enabled to false in the editor/filemanager/connectors/cfm/config.cfm file.
2. Remove unused cfm files under editor/filemanager/connectors/cfm directory of the FCKeditor.
3. Inspect FCKeditor directories for content that has already been uploaded. The uploaded files go under the directory specified in the config.UserFilesPath set in config.cfm.

This posting is provided "AS IS" with no warranties and confers no rights.

About this Entry

This page contains a single entry by David Lenoe published on July 3, 2009 8:02 PM.

Security Bulletin - Adobe Shockwave Player was the previous entry in this blog.

Security Bulletin - ColdFusion is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.