CVE-2000-1050

Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra "/" in the beginning of the request (aka the "extra leading slash").
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:macromedia:jrun:3.0:*:*:*:*:*:*:*
cpe:2.3:a:macromedia:jrun:3.0:sp1:*:*:*:*:*:*

History

20 Nov 2024, 23:33

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=97236316510117&w=2 - () http://marc.info/?l=bugtraq&m=97236316510117&w=2 -
References () http://www.allaire.com/handlers/index.cfm?ID=17966&Method=Full - Patch, Vendor Advisory () http://www.allaire.com/handlers/index.cfm?ID=17966&Method=Full - Patch, Vendor Advisory
References () http://www.osvdb.org/500 - () http://www.osvdb.org/500 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/5407 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/5407 -

Information

Published : 2000-12-11 05:00

Updated : 2024-11-20 23:33


NVD link : CVE-2000-1050

Mitre link : CVE-2000-1050

CVE.ORG link : CVE-2000-1050


JSON object : View

Products Affected

macromedia

  • jrun