We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
80,258 News Articles

Adobe to patch ColdFusion bug next week

FCKEditor flaw compromises multiple sites

Adobe Systems will have a patch ready next week for a flaw in its ColdFusion web development software that other security authorities say could result in a hacked system.

The problem lies in the FCKEditor rich text editor, which is installed with ColdFusion 8, Adobe said on its security blog. Adobe also listed in its warning three steps that could in the meantime mitigate an attack.

FCKEditor is an open-source application that handles file uploads and file management, but the feature is supposed to be disabled in the version embedded on a ColdFusion server, wrote John Mason, a ColdFusion consultant who writes a blog called CodFusion. In some cases, the connector that enables the feature is left on.

"If left on, this means a hacker might be able to directly call the file manager system to upload files and take control of the server," Mason wrote. "FCKEditor has had some history on being exploited by this type of attack."

The SANS Internet Storm Center, which monitors security threats, said it had seen a "high number" of websites running ColdFusion that had been compromised.

"The attacks we've been seeing in the wild end up with inserted tags into documents on compromised websites," wrote Bojan Zdrnja of the Internet Storm Center.

"As you can probably guess by now, the script tags point to a whole chain of websites which ultimately serve malware and try to exploit vulnerabilities on clients."

PC security reviews and advice

Zdrnja wrote on the Internet Storm Center's blog that there appear to be two attack vectors. ColdFusion version 8.0.1 installs a vulnerable version of FCKEditor, which can be directly exploited and allow a hacker to upload arbitrary files.

Other third-party applications also use FCKEditor, such as CFWebstore, which is an e-commerce application for ColdFusion, Zdrnja wrote. CFWebstore has also been exploited in the attacks, he wrote.

IDG UK Sites

Android Wear update new features and release date: Google takes on Apple Watch with software update

IDG UK Sites

15 analogue facts that today's kids won't understand: winding tapes, Ceefax and more

IDG UK Sites

Disney's felt-based 3D printer creates soft toys and other squishy things

IDG UK Sites

WWDC 2015: What Apple will launch at WWDC 2015: Apple TV, Macs, more & how to get WWDC tickets