hwaldron
Posts: 553
Score: 270 Joined: 9/12/2002 From: Roanoke VA, USA Status: offline
|
Web ADMINS should ensure the HTML text editor is secured as it may be automatically installed by default on some versions of Cold Fusion studio. Large # of Cold Fusion web sites compromised in past 24 hours http://isc.sans.org/diary.html?storyid=6715 QUOTE: There have been a high number of Cold Fusion web sites being compromised in last 24 hours. It appears that the attackers are exploiting web sites which have older installations of some Cold Fusion applications. These applications have vulnerable installations of FCKEditor, which is a very popular HTML text editor, or CKFinder, which is an Ajax file manager. The vulnerable installations allow the attackers to upload ASP or Cold Fusion shells which further allow them to take complete control over the server. It appears that there are two attack vectors (both using vulnerable FCKEditor installations though) that the attackers are exploiting. How to disable the HTML editor to improve safety http://www.codfusion.com/blog/post.cfm/cf8-and-fckeditor-security-threat
_____________________________
Harry Waldron - Security News & Best Practices Blog
|