Vulnerability Name: | CVE-2001-0926 (CCN-7622) | ||||||||
Assigned: | 2001-11-27 | ||||||||
Published: | 2001-11-27 | ||||||||
Updated: | 2017-12-19 | ||||||||
Summary: | SSIFilter in Allaire JRun 3.1, 3.0 and 2.3.3 allows remote attackers to obtain source code for Java server pages (.jsp) and other files in the web root via an HTTP request for a non-existent SSI page, in which the request's body has an #include statement. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2001-0926 Source: BUGTRAQ Type: UNKNOWN 20011128 JRun SSI Request Body Parsing Source: CCN Type: Netcraft Security Advisory 2001-11.1 JRun SSI Request Body Parsing Source: CCN Type: Macromedia Product Security Bulletin MPSB01-12 Workaround Addresses JRun Server SSIFilter Security Issue. Source: CONFIRM Type: Patch, Vendor Advisory http://www.macromedia.com/v1/handlers/index.cfm?ID=22261&Method=Full Source: CCN Type: OSVDB ID: 6629 Allaire JRun SSIFilter JSP Source Code Disclosure Source: BID Type: Patch, Vendor Advisory 3589 Source: CCN Type: BID-3589 Allaire JRun SSI Arbitrary File Source Disclosure Vulnerability Source: XF Type: UNKNOWN allaire-jrun-view-source(7622) Source: XF Type: UNKNOWN allaire-jrun-view-source(7622) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |