漏洞信息详情
Allaire ClusterCATS URL重定向漏洞
- CNNVD编号:CNNVD-200005-032
- 危害等级: 低危
- CVE编号:
CVE-2000-0382
- 漏洞类型:
设计错误
- 发布时间:
2000-05-08
- 威胁类型:
远程
- 更新时间:
2005-05-02
- 厂 商:
allaire - 漏洞来源:
Publicized by Alla… -
漏洞简介
ColdFusion ClusterCATS 在HTML重定向时附加过期请求字符串参数,存在漏洞,可能提供重定向站点敏感信息。
漏洞公告
Allaire has released a patch which rectifies this issue. Follow these steps to apply the patch:
1.Stop the Bright Tiger service on each server through control panel – services.
2.Go to the cfusion\brighttiger\program directory and rename teserver.dll to teserver.old
3.Copy the new teserver.dll file into the brighttiger\program directory on each server.
4.Start the Bright Tiger service on each server.
Allaire ClusterCATS 1.0
-
Allaire teserverThose running versions of ColdFusion prior to 4.5.1 must upgrade to 4.5.1 before applying the patch.
ftp://ftp.allaire.com/outgoing/clustercats/teserver.dll
参考网址
来源: ALLAIRE
名称: ASB00-12
链接:http://www.allaire.com/handlers/index.cfm?ID=15697&Method=Full
来源: BID
名称: 1179
链接:http://www.securityfocus.com/bid/1179
受影响实体
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END