Christine,

The CF8 security hotfix for FCKeditor causes that 403 response for any
URI containing /fckeditor/editor/filemanager/ given that there are
security issues with the old versions of FCKeditor, this is probably a
good thing. I would recommend that you upgrade to the latest version
of FCKeditor or CKeditor, or ensure that you have a secure file
manager, and rename the fckeditor folder.

I wrote a blog entry about this issue here:
http://www.petefreitag.com/item/718.cfm

--
Pete Freitag
http://foundeo.com/ - ColdFusion Consulting & Products
http://hackmycfc.om/ - Is your ColdFusion Server Secure?

On Mon, Apr 5, 2010 at 2:04 PM, Christine Olson <[email protected]> wrote:
>
> When our provider updated ColdFusion, our FCKeditor filebrowser ceased 
> working. When we go to browse for a file or image we get the following error.
>
>
> The server didn't send back a proper XML response. Please contact your system 
> administrator.
>
>
> XML request error: Access denied. (403)
>
>
> Requested URL:
> http://education.uic.edu/CMS/fckeditor/editor/filemanager/browser/default/../../connectors/cfm/connector.cfm?Command=GetFoldersAndFiles&Type=Image&CurrentFolder=%2F&uuid=1270488145289
>
>
> Response text:
> <head><title>JRun Servlet Error</title></head><h1>403 </h1><body>
>
>
> <pre>
>
>
> Access denied.</pre></body>
>
>
> I have found many posts and solutions for this error but they point to 
> directories that don't exist in my fckeditor (v. 2.x)(set up by a no longer 
> available consultant)
>
>
> I am not getting any help from my provider and the natives are getting 
> restless. If anyone can help, I would be eternally greatful.
>
>
> Christine Olson
> .
>
> 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Want to reach the ColdFusion community with something they want? Let them know 
on the House of Fusion mailing lists
Archive: 
http://www.houseoffusion.com/groups/cf-talk/message.cfm/messageid:332818
Subscription: http://www.houseoffusion.com/groups/cf-talk/subscribe.cfm
Unsubscribe: http://www.houseoffusion.com/groups/cf-talk/unsubscribe.cfm

Reply via email to