Vulnerabilities > CVE-2002-1855 - Unspecified vulnerability in Macromedia Jrun 3.0/3.1/4.0

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
macromedia
nessus

Summary

Macromedia JRun 3.0 through 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

Vulnerable Configurations

Part Description Count
Application
Macromedia
3

Nessus

NASL familyCGI abuses
NASL idGENERIC_WEB-INF.NASL
descriptionBy making a specially-formatted request to the remote web server, it is possible to retrieve files located under the
last seen2020-06-01
modified2020-06-02
plugin id11037
published2002-07-01
reporterThis script is Copyright (C) 2002-2018 Matt Moore
sourcehttps://www.tenable.com/plugins/nessus/11037
titleMultiple Server Crafted Request WEB-INF Directory Information Disclosure