Allaire Security Bulletin (ASB00- 32) Microsoft (MS00-086): Patch Available for "Web Server File Request Parsing" Vulnerability
Microsoft has released a patch that eliminates a security vulnerability in Microsoft® Internet Information Services 5.0, that could enable a malicious user to run operating system commands on a web server. This is not a problem with the ColdFusion Server, but it is an issue that can affect ColdFusion users, as described in the Issue section. Allaire recommends that customers follow the instructions posted on the Microsoft Web site to address this issue.
Allaire Security Bulletin (ASB00-32) Microsoft (MS00-086): Patch Available for "Web Server File Request Parsing" Vulnerability