Skip to main content
October 9, 2009
Question

CF 8- security scan pins fckeditor issue after hotfix applied

  • October 9, 2009
  • 1 reply
  • 532 views

Howdy,

We're trying to get a new web site launched on CF8. We are running 8.0.1, and I've applied the fckeditor vulnerability hotfix. The hotfix

file shows up in the update field and classpath, and the file appears to be located where the hotfix notes say it should be. I removed the two connector files in the hotfix notes, since we don't need fckeditor for uploads.

Our client is using McAfee Secure to run a security scan on the site, and it repeatedly points up the fckeditor vulnerability, even though the hotfix has been applied.

I've checked and double checked the hotfix installation, stopped and restarted CF, rebooted the server, and still the scans insist the vulnerability remains.

I'm about at my wit's end, and the client is ready to pull the project.

Anybody had this kind of problem? Any ideas?

Thanks very much for your time and attention.

    This topic has been closed for replies.

    1 reply

    Inspiring
    October 10, 2009

    Hi,

    It might be because of the "Privacy Service" module which comes along with the "McCafe", try removing that using the McCafe uninstallation tools.

    HTH