Macromedia JRun Management Console HTML Injection Vulnerability
BID:11411
Info
Macromedia JRun Management Console HTML Injection Vulnerability
| Bugtraq ID: | 11411 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 14 2004 12:00AM |
| Updated: | Oct 14 2004 12:00AM |
| Credit: | Discovery is credited to ACROS Security. |
| Vulnerable: |
Macromedia JRun 4.0 SP1a Macromedia JRun 4.0 SP1 Macromedia JRun 4.0 build 61650 Macromedia JRun 4.0 |
| Not Vulnerable: | |
Discussion
Macromedia JRun Management Console HTML Injection Vulnerability
Macromedia JRun is prone to an HTML injection vulnerability. This issue exists in the Management Console and may allow hijacking of administrative sessions.
Macromedia JRun is prone to an HTML injection vulnerability. This issue exists in the Management Console and may allow hijacking of administrative sessions.
Exploit / POC
Macromedia JRun Management Console HTML Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Macromedia JRun Management Console HTML Injection Vulnerability
Solution:
This issue was addressed by Macromedia Security Bulletin MPSB04-08. Fixes may be applied with the JRun Update 4 tool that is available from the JRun Support Center.
Solution:
This issue was addressed by Macromedia Security Bulletin MPSB04-08. Fixes may be applied with the JRun Update 4 tool that is available from the JRun Support Center.
References
Macromedia JRun Management Console HTML Injection Vulnerability
References:
References:
- Macromedia JRun Support Center - Updaters (Macromedia)
- MPSB04-08 - Cumulative Security Patch available for JRun server (Macromedia)
- ACROS Security: HTML Injection in JRun Management Console ("ACROS Security"
)