PT-2001-2630 · Macromedia · Macromedia Jrun

Publicado

2001-12-31

·

Atualizado

2008-09-05

·

CVE-2001-1545

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Macromedia JRun versions 3.0 and 3.1
Description The issue allows remote attackers to obtain session IDs and hijack sessions. This can occur via HTTP referrer fields or sniffing when client browsers have cookies enabled and the session ID is appended to URL requests.
Recommendations For Macromedia JRun versions 3.0 and 3.1, consider disabling the session ID rewriting feature to prevent session hijacking until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-1545

Produtos afetados

Macromedia Jrun