CVE-2001-1513
N/A
N/A
Summary
Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing '/' (slash), as demonstrated using ctx.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.macromedia.com/v1/handlers/index.cfm?ID=22260&Method=Full
- http://www.iss.net/security_center/static/7680.php
- http://www.securityfocus.com/bid/3600
References
- http://www.macromedia.com/v1/handlers/index.cfm?ID=22260&Method=Full
- http://www.iss.net/security_center/static/7680.php
- http://www.securityfocus.com/bid/3600
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.