CVE-2001-0926

SSIFilter in Allaire JRun 3.1, 3.0 and 2.3.3 allows remote attackers to obtain source code for Java server pages (.jsp) and other files in the web root via an HTTP request for a non-existent SSI page, in which the request's body has an #include statement.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:macromedia:jrun:2.3.3:*:*:*:*:*:*:*
cpe:2.3:a:macromedia:jrun:3.0:*:*:*:*:*:*:*
cpe:2.3:a:macromedia:jrun:3.1:*:*:*:*:*:*:*

History

20 Nov 2024, 23:36

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=100697797325013&w=2 - () http://marc.info/?l=bugtraq&m=100697797325013&w=2 -
References () http://www.macromedia.com/v1/handlers/index.cfm?ID=22261&Method=Full - Patch, Vendor Advisory () http://www.macromedia.com/v1/handlers/index.cfm?ID=22261&Method=Full - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/3589 - Patch, Vendor Advisory () http://www.securityfocus.com/bid/3589 - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/7622 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/7622 -

Information

Published : 2001-11-28 05:00

Updated : 2024-11-20 23:36


NVD link : CVE-2001-0926

Mitre link : CVE-2001-0926

CVE.ORG link : CVE-2001-0926


JSON object : View

Products Affected

macromedia

  • jrun