PT-2001-2598 · Macromedia · Macromedia Jrun

Published

2001-12-31

·

Updated

2008-09-10

·

CVE-2001-1513

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Macromedia JRun versions 3.0 through 3.1
Description The issue allows remote attackers to obtain duplicate active user session IDs and perform actions as other users. This can be achieved by making a URL request for the web application directory without the trailing '/' (slash).
Recommendations For Macromedia JRun versions 3.0 through 3.1, ensure that URL requests for the web application directory include a trailing '/' (slash) to prevent duplicate active user session IDs from being obtained. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1513

Affected Products

Macromedia Jrun