Allaire Security Bulletin (ASB00-31) : Microsoft (MS00-080): Patch Available for "Session ID Cookie Marking" Vulnerability
Microsoft has released a patch that eliminates a security vulnerability in Microsoft(r) Internet Information Server. The vulnerability could allow a malicious user to "hijack" another user's secure web session, under a very restricted set of circumstances. This is not a problem with the ColdFusion Server, but it is an issue that can affect ColdFusion users, as described in the Issue section. Allaire recommends that customers follow the instructions posted on the Microsoft Web site to address this issue.
Allaire Security Bulletin (ASB00-31)
Microsoft (MS00-080): Patch Available for "Session ID Cookie Marking" Vulnerability