Malformed .HTR Request Allows Reading of File Fragments

 
May 07, 2001
Microsoft has released a patch for a vulnerability which could allow an attacker to request a file in a way that would cause it to be processed by the .HTR ISAPI extension. The result of doing this is that fragments of server-side files could potentially be sent to the attacker. Macromedia customers who have previously disabled the .HTR functionality would not be affected by this vulnerability.

Note: This is not a problem with ColdFusion Server or the JRun Server, but it is an issue that can affect ColdFusion and JRun users as described in the Microsoft Security Bulletin mentioned below. Macromedia recommends that customers follow the instructions posted on the Microsoft Web Site to address this issue.

Customer Security Bulletin (CSB01-02): Microsoft (MS01-004): Malformed .HTR Request Allows Reading of File Fragments


Privacy | FAQ | Site Map | About | Guidelines | Contact | Advertising | What is ColdFusion?
House of Fusion | ColdFusion Jobs | Blog of Fusion | AHP Hosting