Website Security Hole Found and Patched

 
May 08, 2002

Deerfield.com (current distributors of Website) has released a service pack for WebSite Pro that will address a possible source code disclosure from active documents, such as ASP or ColdFusion. This security problem is present in all current versions of the product as well as past versions.

Download WebSite 3.1.13.0 (which contains the service pack mentioned above): http://www.deerfield.com/download/website/

Release Notes: http://www.deerfield.com/support/website/releasenotes/

Bob Denny, author of Website, also mentioned this workaround to the problem: "Don't use any active documents with file extensions longer than 3 characters. Remove the mapping for .html-ssi or change it to .ssi and rename all your .html-ssi documents. Fix all the links to same. I know it's ugly, but upgrading would solve the problem."

Add a Comment
(If you subscribe, any new posts to this thread will be sent to your email address.)
  
Privacy | FAQ | Site Map | About | Guidelines | Contact | Advertising | What is ColdFusion?
House of Fusion | ColdFusion Jobs | Blog of Fusion | AHP Hosting