From: "Gareth Cole" <gareth.c...@esus.ie>
Date: Mon, 6 Jul 2009 16:55:04 +0100
Local: Mon 6 July 2009 16:55
Subject: RE: [SCFUG] Re: file upload vulnerability in CF801
Hi Stephen,
I'd argue that it is a CF vulnerability.
With manual installs of fckeditor, you have to explicitly enable file
With CF8.01, it automatically enables un-authenticated file upload
Adobe seem to agree: http://blogs.adobe.com/psirt/2009/07/
On Behalf Of Stephen Moretti
Just so you are aware its not a ColdFusion vunerability. Its a general
2009/7/3 Gareth Cole <gareth.c...@esus.ie>
Hi Folks,
Just in case you haven't seen this yet, there's a security vulnerability in
http://www.theregister.co.uk/2009/07/03/coldfusion_compromise/
Some genius at adobe decided to enable file uploads by default in the
The link has full details and remedy.
-- You must Sign in before you can post messages.
To post a message, you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||