PT-2001-2630 · Macromedia · Macromedia Jrun

Published

2001-12-31

·

Updated

2008-09-05

·

CVE-2001-1545

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Macromedia JRun versions 3.0 and 3.1
Description The issue allows remote attackers to obtain session IDs and hijack sessions. This can occur via HTTP referrer fields or sniffing when client browsers have cookies enabled and the session ID is appended to URL requests.
Recommendations For Macromedia JRun versions 3.0 and 3.1, consider disabling the session ID rewriting feature to prevent session hijacking until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1545

Affected Products

Macromedia Jrun