On Tue, Jan 20, 2009 at 8:00 AM, James Holmes wrote:
> We have sandboxing turned on; while just about everything works as you
> would expect without it, it appears that for some functionality
> (including cffeed) the path to [coldfusion
> instance]/WEB-INF/cfusion/lib needs to be added to the sandbox.

That is a bug that was most likely introduced in APSB08-21:
http://www.adobe.com/support/security/bulletins/apsb08-21.html

What permissions did you give exactly? Was execute enough? All other
permissions are potentially dangerous for the server integrity.
Although since you allow Java in your Sandboxes anybody can escalate
his own privileges anyway.

Jochem


-- 
Jochem van Dieten
http://jochem.vandieten.net/

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Adobe® ColdFusion® 8 software 8 is the most important and dramatic release to 
date
Get the Free Trial
http://ad.doubleclick.net/clk;207172674;29440083;f

Archive: 
http://www.houseoffusion.com/groups/cf-talk/message.cfm/messageid:318267
Subscription: http://www.houseoffusion.com/groups/cf-talk/subscribe.cfm
Unsubscribe: 
http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=11502.10531.4

Reply via email to