PT-2000-1475 · Allaire · Jrun

Published

2000-06-22

·

Updated

2017-10-10

·

CVE-2000-0540

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Allaire JRun versions 2.3.x
Description The issue allows remote attackers to access arbitrary files or obtain configuration information through JSP sample files. For example, this can be achieved via the 'viewsource.jsp' file.
Recommendations For Allaire JRun versions 2.3.x, remove or restrict access to the JSP sample files to prevent exploitation. As a temporary workaround, consider restricting access to the 'viewsource.jsp' file until a more permanent solution is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0540

Affected Products

Jrun