
60
Setting
Default
Recommendation
Description
Enable Global
Script Protection
Unchecked
Understand
limitations
,
Checked
This setting provides
very limited
protection
against certain Cross
Site Scripting attack vectors. It is
important to understand that
enabling
this setting does not
protect your site from all possible
Cross Site Scripting attacks
.
When this setting is turned on it uses
a regular expression defined in the
file
neo-security.xml
to
replace input variables containing
following tags:
object
,
embed
,
script
,
applet
,
meta
with
InvalidTag
. This setting does not
restrict any javascript strings that
may be injected and executed,
iframe tags, or any XSS obfuscation
techniques. See Appendix A.13 for
more information on XSS attack
vectors.
Default ScriptSrc
Directory
/CFIDE/scripts/
/
somewhere-else
/
Because the scripts directory also
contains CFML source code (such
as FCKeditor), you should move this
directory to a non-default location.
Содержание 38043740 - ColdFusion Standard - Mac
Страница 5: ...5 ...
Страница 12: ...12 Next Click Add Roles and select the checkbox next to Web Server IIS ...
Страница 26: ...26 ...
Страница 33: ...33 ...
Страница 36: ...36 Select an install directory a non standard directory location on a non system partition is preferred ...
Страница 38: ...38 ...