Allaire JRun Web Root Directory Disclosure Vulnerability
BID:3592
Info
Allaire JRun Web Root Directory Disclosure Vulnerability
| Bugtraq ID: | 3592 |
| Class: | Unknown |
| CVE: |
CVE-2001-1510 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 27 2001 12:00AM |
| Updated: | Nov 03 2009 03:27PM |
| Credit: | Discovered by George Hedfors <[email protected]> of Defcom Labs and published in Macromedia Product Security Bulletin (MPSB01-13) on November 27, 2001. |
| Vulnerable: |
Macromedia JRun 3.1 Macromedia JRun 3.0 |
| Not Vulnerable: | |
Discussion
Allaire JRun Web Root Directory Disclosure Vulnerability
Allaire JRun is a development suite with JSP and Java Servlets for developing web applications.
Allaire JRun is prone to an information-disclosure vulnerability because it fails to handle malformed URLs properly. A remote attacker could access the contents under the webserver root directory.
Submitting a request for 'http://server/%3f.jsp' could cause JRun to reveal the contents within the web root. It's also possible to view the contents of any subdirectories along with ACL-protected resources.
The attacker could exploit this issue to obtain the source of known files residing on the host, including ASP files.
NOTE: This vulnerability was originally reported to work on Microsoft IIS hosts only, but other webservers (Apache, Jetty) have been reported vulnerable.
Allaire JRun is a development suite with JSP and Java Servlets for developing web applications.
Allaire JRun is prone to an information-disclosure vulnerability because it fails to handle malformed URLs properly. A remote attacker could access the contents under the webserver root directory.
Submitting a request for 'http://server/%3f.jsp' could cause JRun to reveal the contents within the web root. It's also possible to view the contents of any subdirectories along with ACL-protected resources.
The attacker could exploit this issue to obtain the source of known files residing on the host, including ASP files.
NOTE: This vulnerability was originally reported to work on Microsoft IIS hosts only, but other webservers (Apache, Jetty) have been reported vulnerable.
Solution / Fix
Allaire JRun Web Root Directory Disclosure Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Allaire JRun Web Root Directory Disclosure Vulnerability
References:
References:
- JRun Product Homepage (Allaire)