CENTER.HU groups
CENTER.HU address

User:

Guest

www.center.hu / Archive / Security news / october, 2004 / Contents disclosure in ColdFusion MX 6.1 on IIS 

Contents disclosure in ColdFusion MX 6.1 on IIS

Contents disclosure in ColdFusion MX 6.1 on IIS

Madrid, October 7 2004 - According to SecuriTeam, a vulnerability has been detected in input validation in ColdFusion MX 6.1 -on Internet Information Server(IIS)-, which could lead to content disclosure.

This security flaw could make it possible to view the content of files stored under the web root -bypassing access restrictions configured in the ISS management system. To exploit the vulnerability, it would be necessary to be aware of the existence of the file and its name.

Macromedia has published -at
http://www.macromedia.com/devnet/security/security_zone/mpsb04-09.html - an update to correct the problem.

NOTE: The addresses above may not show up on your screen as single lines. This would prevent you from using the links to access the web pages. If this happens, just use the ´cut´ and ´paste´ options to join the pieces of the URL.


Oxygen3 24h-365d,
by Panda Software

Back




Copyright © CENTER.HU Ltd, 2000-2010. All rights reserved

sitemap | privacy policy |

copyrights | new pages |

terms of purchase | contact us


PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel