CVE-2001-1545
N/A
N/A
Summary
Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers to obtain session IDs and hijack sessions via HTTP referrer fields or sniffing.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.macromedia.com/v1/handlers/index.cfm?ID=22291&Method=Full
- http://www.iss.net/security_center/static/7679.php
- http://www.securityfocus.com/bid/3665
References
- http://www.macromedia.com/v1/handlers/index.cfm?ID=22291&Method=Full
- http://www.iss.net/security_center/static/7679.php
- http://www.securityfocus.com/bid/3665
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.