Vulnerabilities > CVE-2001-1544 - Unspecified vulnerability in Macromedia Jrun 2.3.3/3.0/3.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN macromedia
nessus
Summary
Directory traversal vulnerability in Macromedia JRun Web Server (JWS) 2.3.3, 3.0 and 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Nessus
NASL family | CGI abuses |
NASL id | DDI_JRUN_TRAVERSAL.NASL |
description | This host is running the Allaire JRun web server. Versions 2.3.3, 3.0, and 3.1 are vulnerable to a directory traversal attack. This allows a potential intruder to view the contents of any file on the system. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 10997 |
published | 2002-06-05 |
reporter | This script is Copyright (C) 2002-2018 Digital Defense Inc. |
source | https://www.tenable.com/plugins/nessus/10997 |
title | JRun Web Server (JWS) GET Request Traversal Arbitrary File Access |
code |
|
References
- http://www.iss.net/security_center/static/7678.php
- http://www.iss.net/security_center/static/7678.php
- http://www.macromedia.com/v1/handlers/index.cfm?ID=22290&Method=Full
- http://www.macromedia.com/v1/handlers/index.cfm?ID=22290&Method=Full
- http://www.securityfocus.com/bid/3666
- http://www.securityfocus.com/bid/3666