Re: CF 8 Security issue and related hotfix

2008-11-10 Thread Tom Chiverton
On Friday 07 Nov 2008, James Holmes wrote: It's easy to miss since Adobe have chosen not to update the hotfix list: The security blog RSS feed picked it up. -- Tom Chiverton Helping to challengingly morph infrastructures This email is

CF 8 Security issue and related hotfix

2008-11-06 Thread James Holmes
I hope everyone is aware of this: http://www.adobe.com/support/security/bulletins/apsb08-21.html It's easy to miss since Adobe have chosen not to update the hotfix list: http://kb.adobe.com/selfservice/viewContent.do?externalId=kb402604 mxAjax / CFAjax docs and other useful articles:

Re: CF 8 Security issue and related hotfix

2008-11-06 Thread James Holmes
Ah, I see the hotfix install guide was written using the cut and paste random hotfix instructions method of documentation building: 1. Stop all ColdFusion services. -- ok, no problem 2. Download and unzip the hot fix. (51K) -- yep, done, although it's a jar so there's nothing to unzip 3.