Web applications written with the ColdFusion development tools are now targeted by hackers.
According to security firm SANS, a series of attacks aiming at flaws plaguing previous vesrsions of ColdFusion development apps, known as the FCKEditor text editing tool and the CKFinder file management tool.
SANS researcher Bojan Zdrnja said, "The attacks we’ve been seeing in the wild end up with inserted <script > tags into documents on compromised web sites."
"As you can probably guess by now, the script tags point to a whole chain of web sites which ultimately serve malware and try to exploit vulnerabilities on clients."
SANS recommend that all applications must be fully updated and that administrators should identify obsolete ColdFusion apps which could be a potential target of hackers.






Littlefish Support
Littlefish Support+
Managed NOC
Non-Contract Services
Our Culture
Testimonials
Carbon Friendly
Jobs


