back to article Still using ColdFusion? Really? Well, you'll want to install this patch

Adobe is advising users and administrators running ColdFusion to patch their software following the release of a security fix for an information disclosure vulnerability. The ColdFusion HotFix addresses a vulnerability in the handling of XML data for ColdFusion 10 and 11. Both patches address a single CVE-listed security …

    1. Gary F

      Re: Still using ColdFusion?

      Why not? It's still current and Adobe are developing version 12 which is in beta right now. There are also open source versions such as Lucee which was launched earlier this year.

      1. Anonymous Coward
        Anonymous Coward

        Re: Still using ColdFusion?

        Lucee (and railo before it) use fairly old versions of most libraries, BlazeDS is at

    2. War President

      Re: Still using ColdFusion?

      Combine equal parts legacy web applications, no developer resources to spare, an institutional resistance to change, and the fact that it just plain works.

    3. sisk

      Re: Still using ColdFusion?

      Because it works, we've been using it since the 90s, and (most importantly) the people who get to make decisions cringe when I bring up LAMP servers.

  2. channel extended


    Another day, another Adobe security fail. :(

    1. Gary F

      Re: SDSS

      Why is it a fail if they've just released a patch for it? That's a good thing. It's a fail if they didn't get round to it.

      Adobe: I would like a complimentary subscription to Creative Cloud please. Thank you. ;-)

  3. DrewPalmer_FL

    ColdFusion rocks

    It bewilders me why anyone uses anything else for DB driven websites.

    So much faster to develop with than anything else, and who cares about a $5K license if you are a real company? Python is awesomely robust but very few sites need the granularity it provides; node and PHP seem to take more time to comment than to actually code.

