This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Cold Fusion sites compromised

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Cold Fusion sites compromised
- http://isc.sans.org/diary.html?storyid=6715
Last Updated: 2009-07-03 09:35:14 UTC …(Version: 2) - "There have been a high number of Cold Fusion web sites being compromised in last 24 hours… It appears that the attackers are exploiting web sites which have older installations of some Cold Fusion applications. These applications have vulnerable installations of FCKEditor, which is a very popular HTML text editor, or CKFinder, which is an Ajax file manager. The vulnerable installations allow the attackers to upload ASP or Cold Fusion shells which further allow them to take complete control over the server. The attacks we've been seeing in the wild end up with inserted
FYI…

Hotfix available for potential ColdFusion 8 input sanitization issue
- http://www.adobe.com/support/security/bull…/apsb09-09.html
July 8, 2009 - "… Adobe recommends affected ColdFusion customers update their installation using the instructions below:
NOTE: ColdFusion 8 customers who have not already done so should first update to ColdFusion 8.0.1*
* http://www.adobe.com/support/coldfusion/do…pdates.html#cf8 …
Severity rating: Adobe categorizes this as a critical issue and recommends affected users patch their installations…"
Revisions: July 9, 2009 - Bulletin updated with Acknowledgment and information on ColdFusion 8.0 hotfix
(More detail and links at the first URL above.)

- http://secunia.com/advisories/35747/2/
Release Date: 2009-07-09
Critical: Highly critical
Impact: Exposure of system information, Exposure of sensitive information, System access
Solution: Update to version 8.0.1 and apply hot fix…

- http://blog.trendmicro.com/coldfusion-spur…ass-compromise/
July 8, 2009

:ph34r:
FYI…

Adobe ColdFusion / JRun multiple vulns - updates available
- http://secunia.com/advisories/36329/2/
Release Date: 2009-08-18
Critical: Moderately critical
Impact: Security Bypass, Cross Site Scripting, Exposure of system information, Exposure of sensitive information, System access
Where: From remote
Solution Status: Vendor Patch
Software: Adobe ColdFusion 8.x, Adobe ColdFusion MX 7.x, Macromedia Jrun 4.x …
Original Advisory: Adobe:
http://www.adobe.com/support/security/bull…/apsb09-12.html
"… Adobe categorizes these as critical issues and recommends affected users patch their installations…"

- http://www.adobe.com/support/security/bull…/apsb09-12.html
August 21, 2009 - Bulletin updated with additional information regarding CVE-2009-1876.

> http://download.macromedia.com/pub/coldfus…e_1872_1877.txt
"ColdFusion… hotfix includes fixes for CVE-2009-1872, CVE-2009-1877…"
> http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-1872
> http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-1877

> http://download.macromedia.com/pub/coldfus…ReadMe_1875.txt
"ColdFusion… hotfix for ColdFusion 7.0.2, ColdFusion 8, ColdFusion 8.0.1…"
> http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-1875

> http://download.macromedia.com/pub/coldfus…ReadMe_1876.txt
"ColdFusion… fix for CVE-2009-1876…"
> http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-1876

> http://download.macromedia.com/pub/coldfus…ReadMe_1878.txt
"… hotfix for ColdFusion 7.0.2, ColdFusion 8, ColdFusion 8.0.1.."
> http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-1878

> http://www.adobe.com/support/security/bull…/apsb09-12.html
August 28, 2009 - Bulletin updated with additional information regarding CVE-2009-1873, CVE-2009-1874, and CVE-2009-1876.
- http://download.macromedia.com/pub/coldfus…e_1873_1874.txt
- http://download.macromedia.com/pub/coldfus…ReadMe_1876.txt

- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-1873
- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-1874
- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-1876

:ph34r: :ph34r: