 |
|
|
Macromedia JRun Server Multiple Vulnerabilities
Last
Updated:
November 30, 1999
Macromedia JRun Server Multiple Vulnerabilities may allow the following.
-Hijacking
-Cross Site Scripting
-Exposure of sensitive information
-DoS
Affected Software Versions
JRun 4.0 (all editions)
JRun 3.1 (all editions)
JRun 3.0 (all editions)
Successful exploitation requires that "verbose" debug mode is enabled for the JRun web server connectors (not enabled by default).
URL parsing error can be exploited to show the source of any file such as script files inside the web root by adding ";.cfm" to the end of a URL. |
|
 |
|