There is a critical point in FCKeditor, who was announced some time, when detected in connectors ASP and PHP.
PHP - GeekLog v1.4.0 FckEditor File Upload Security Vulnerability
ASP - Exploiting IIS via HTMLEncode (MS08-006)
Now this vulnerability was detected in the version 8.0.1 of ColdFusion, the version 8.0 apparently does not suffer of this failure, but it is worth check.
Many local are supplying information to prevent frights.
Problem safety serious in CF 8.01
CF8 and FCKEditor Security Threat
ColdFusion 8 FCKeditor Vulnerability
I recommend disable filemanager.
http://blog.pcsilva.com/en/trackback.cfm?451D8093-C298-ED05-B026FE3D8516AC6C









There are no comments for this entry.
[Add Comment] [Subscribe to Comments]