[cfaussie] Security update: Hotfix available for ColdFusion

2010-08-11 Thread Kai Koenig
Sorry for the crosspost to the NZ and AU lists, but you might want to install this one rather sooner than later: http://www.adobe.com/support/security/bulletins/apsb10-18.html Cheers Kai -- Kai Koenig - Ventego Creative Ltd ph: +64 4 476 6781 - mob: +64 21 928 365 / +61 450 132 117 web:

RE: [cfaussie] Security update: Hotfix available for ColdFusion

2010-08-11 Thread Steve Onnis
They couldn't give more information about the actual security issue?? -Original Message- From: Kai Koenig [mailto:k...@koeni.de] Sent: Thursday, 12 August 2010 8:39 AM To: cfugauckl...@googlegroups.com; cfaussie@googlegroups.com Subject: [cfaussie] Security update: Hotfix available for

Re: [cfaussie] Security update: Hotfix available for ColdFusion

2010-08-11 Thread Kai Koenig
Not to the general public, no. It's a common practice btw (like it or not :-) that vendors don't release the exploit. Cheers, Kai They couldn't give more information about the actual security issue?? -Original Message- From: Kai Koenig [mailto:k...@koeni.de] Sent: Thursday, 12

Re: [cfaussie] Security update: Hotfix available for ColdFusion

2010-08-11 Thread Dmitry Yakhnov
Procheckup has discovered that the ColdFusion admin console (and various programs within) are vulnerable to multiple directory traversal attacks related to a input parameter. No authentication is needed; all that is needed is that the admin console is accessible to the Internet. *The exploit

RE: [cfaussie] Security update: Hotfix available for ColdFusion

2010-08-11 Thread charlie arehart
Well, no, because that would then expose to bad guys how they could use the vulnerability for ill. Really, every shop should apply it, but as it notes, the key is an exposure via the CF Admin, so if you have your CF Admin available to the public, you're vulnerable. If you require web server

[cfaussie] Coldfusion FCK Editor

2010-08-11 Thread Steve Onnis
Does anyone now if you can configure the built FCK Editor to do image uploading? I cant seem to get the browse server button to enable Steve -- You received this message because you are subscribed to the Google Groups cfaussie group. To post to this group, send email to

Re: [cfaussie] Coldfusion FCK Editor

2010-08-11 Thread Mike Kear
Yes you can.It's tricky to do, and you have to have all the relevant paths exactly right. It's not very good at telling you what's wrong if you haven't got it right, but once you get it right it's really good. Once you have got it worked out, you can override any of the default settings

RE: [cfaussie] Coldfusion FCK Editor

2010-08-11 Thread Steve Onnis
I really think Adobe chose poorly with choosing to integrate this editor into the product. It is just soo cumbersome to configure. Everything should be able to be configured using tag attributes...that's what ColdFusion is! If I want to specify an upload path for the editor it should be passed

Re: [cfaussie] Coldfusion FCK Editor

2010-08-11 Thread Kym Kovan
On 12/08/2010 12:26, Steve Onnis wrote: Does anyone now if you can configure the built FCK Editor to do image uploading? I cant seem to get the browse server button to enable Steve Adding to what Mike just wrote its turned off by default as it is a security risk, there was a patch came out a

[cfaussie] Recursive function giving me 500 null error

2010-08-11 Thread Seona Bellamy
Hi guys, Trying to make a little helper tool for an online game that I play. The game has a very complex crafting system, and I'm trying to put together something to allow me to select an item I can craft and find out: a) all the things I need to make that item, all the way back to the raw

[cfaussie] Re: Recursive function giving me 500 null error

2010-08-11 Thread BarryC
It sounds like your recursive function is either not ending or collecting so many query results it can't handle the amount. Try passing a counter along with your downTree() function e.g. downTree(result,counter), then put a cfabort in downTree() when that counter reaches say 10 (increment the

RE: [cfaussie] Recursive function giving me 500 null error

2010-08-11 Thread Dale Fraser
I'd suggest you have a recursive loop For example Let's say that Item A requires Item B And that Item B requires Item A It will go around in circles and eventually give up. Regards Dale Fraser http://dale.fraser.id.au http://cfmldocs.com http://cfmldocs.com/