We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
80,259 News Articles

Adobe to patch ColdFusion bug next week

FCKEditor flaw compromises multiple sites

Adobe Systems will have a patch ready next week for a flaw in its ColdFusion web development software that other security authorities say could result in a hacked system.

The problem lies in the FCKEditor rich text editor, which is installed with ColdFusion 8, Adobe said on its security blog. Adobe also listed in its warning three steps that could in the meantime mitigate an attack.

FCKEditor is an open-source application that handles file uploads and file management, but the feature is supposed to be disabled in the version embedded on a ColdFusion server, wrote John Mason, a ColdFusion consultant who writes a blog called CodFusion. In some cases, the connector that enables the feature is left on.

"If left on, this means a hacker might be able to directly call the file manager system to upload files and take control of the server," Mason wrote. "FCKEditor has had some history on being exploited by this type of attack."

The SANS Internet Storm Center, which monitors security threats, said it had seen a "high number" of websites running ColdFusion that had been compromised.

"The attacks we've been seeing in the wild end up with inserted tags into documents on compromised websites," wrote Bojan Zdrnja of the Internet Storm Center.

"As you can probably guess by now, the script tags point to a whole chain of websites which ultimately serve malware and try to exploit vulnerabilities on clients."

PC security reviews and advice

Zdrnja wrote on the Internet Storm Center's blog that there appear to be two attack vectors. ColdFusion version 8.0.1 installs a vulnerable version of FCKEditor, which can be directly exploited and allow a hacker to upload arbitrary files.

Other third-party applications also use FCKEditor, such as CFWebstore, which is an e-commerce application for ColdFusion, Zdrnja wrote. CFWebstore has also been exploited in the attacks, he wrote.


IDG UK Sites

Best Christmas 2014 UK tech deals, Boxing Day 2014 UK tech deals & January sales 2015 UK tech...

IDG UK Sites

Apple's 2014 highlights: the most significant Apple news of 2014

IDG UK Sites

Watch this heartwarming Christmas short by Trunk for composer John Rutter

IDG UK Sites

Ultimate iOS 8 Tips: 35 awesome and advanced tips for using iOS 8 on iPhone and iPad