Customer Security Bulletin (CSB01- 07) : Microsoft (MS01- 026): Superfluous Decoding Operation Could Allow Command Execution Via IIS

 
May 21, 2001
Microsoft has released a patch that includes three newly-found vulnerabilities along with cumulative patches reported in prior Microsoft Security Bulletins. The new vulnerabilities include: (1) A vulnerability that could enable an attacker to execute operating system commands on a web server. (2) A vulnerability that could enable an attacker to prevent an FTP server from performing useful work. And (3) a vulnerability could make it easier for an attacker to gain access to a poorly configured network via FTP.

This is not a problem with ColdFusion Server or the JRun Server, but it is an issue that can affect ColdFusion and JRun users as described in the Microsoft Security Bulletin mentioned below. Macromedia recommends that customers follow the instructions posted on the Microsoft Web Site to address this issue.

Superfluous Decoding Operation Could Allow Command Execution Via IIS


Privacy | FAQ | Site Map | About | Guidelines | Contact | Advertising | What is ColdFusion?
House of Fusion | ColdFusion Jobs | Blog of Fusion | AHP Hosting