Cold Fusion sites compromised
- http://isc.sans.org/diary.html?storyid=6715
Last Updated: 2009-07-03 09:35:14 UTC …(Version: 2) - "There have been a high number of Cold Fusion web sites being compromised in last 24 hours… It appears that the attackers are exploiting web sites which have older installations of some Cold Fusion applications. These applications have vulnerable installations of FCKEditor, which is a very popular HTML text editor, or CKFinder, which is an Ajax file manager. The vulnerable installations allow the attackers to upload ASP or Cold Fusion shells which further allow them to take complete control over the server. The attacks we've been seeing in the wild end up with inserted
Hotfix available for potential ColdFusion 8 input sanitization issue
- http://www.adobe.com/support/security/bull…/apsb09-09.html
July 8, 2009 - "… Adobe recommends affected ColdFusion customers update their installation using the instructions below:
NOTE: ColdFusion 8 customers who have not already done so should first update to ColdFusion 8.0.1*
* http://www.adobe.com/support/coldfusion/do…pdates.html#cf8 …
Severity rating: Adobe categorizes this as a critical issue and recommends affected users patch their installations…"
Revisions: July 9, 2009 - Bulletin updated with Acknowledgment and information on ColdFusion 8.0 hotfix (More detail and links at the first URL above.)
- http://secunia.com/advisories/35747/2/
Release Date: 2009-07-09
Critical: Highly critical
Impact: Exposure of system information, Exposure of sensitive information, System access
Solution: Update to version 8.0.1 and apply hot fix…