CVE-2001-1510
N/A
N/A
Summary
Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.iss.net/security_center/static/7623.php
- http://www.securityfocus.com/bid/3592
- http://www.securityfocus.com/archive/1/243636
- http://online.securityfocus.com/archive/1/243203
- http://online.securityfocus.com/archive/1/242843/2002-07-27/2002-08-02/2
- http://www.macromedia.com/v1/handlers/index.cfm?ID=22262&Method=Full
References
- http://www.iss.net/security_center/static/7623.php
- http://www.securityfocus.com/bid/3592
- http://www.securityfocus.com/archive/1/243636
- http://online.securityfocus.com/archive/1/243203
- http://online.securityfocus.com/archive/1/242843/2002-07-27/2002-08-02/2
- http://www.macromedia.com/v1/handlers/index.cfm?ID=22262&Method=Full
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.