Allaire Releases Patch for Spectra 1.0 Remote Access Service Problem
Allaire Security Bulletin (ASB00-04) announces the patch now available for the Allaire Spectra 1.0 Security Authentication System. The Spectra 1.0 Remote Access Service invoke.cfm template normally requires that users must be authenticated in the webtop security context in order to even attempt to use the Remote Access Service. However, without this patch, the user can bypass this.
Within this article, Allaire stresses that it strongly recommends that customers remove all documentation, sample code, example applications, and tutorials from production servers, as well as taking other precautions outlined within.
Allaire Security Bulletin ASB00-04