Madrid, October 7 2004 - According to SecuriTeam, a vulnerability has been detected in input validation in ColdFusion MX 6.1 -on Internet Information Server(IIS)-, which could lead to content disclosure.
This security flaw could make it possible to view the content of files stored under the web root -bypassing access restrictions configured in the ISS management system. To exploit the vulnerability, it would be necessary to be aware of the existence of the file and its name.
Macromedia has published -at
http://www.macromedia.com/devnet/security/security_zone/mpsb04-09.html - an update to correct the problem.
NOTE: The addresses above may not show up on your screen as single lines. This would prevent you from using the links to access the web pages. If this happens, just use the ´cut´ and ´paste´ options to join the pieces of the URL.
Oxygen3 24h-365d,
by Panda Software
Member of IVSZ

Member of SZEK

Acer Affinity Gold partner

Dell Registered Partner
![]()
OKI System Shinrai Partner

XEROX Viszonteladó

APC megbízható szállító

EATON Authorized Partner

Cisco partner

Symantec Software Partner

ESET Partner
![]()
FUJITSU partner

LENOVO Premium Partner

IBM Business Partner

PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel