CVE-2000-1050: Medium severity Macromedia JRun vulnerability
Published Dec 11, 2000
·Updated
Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra "/" in the beginning of the request (aka the "extra leading slash").
Affected Software
2 affected components
Macromedia JRun=3.0
Macromedia JRun=3.0-sp1
Remediation
Event History
Dec 11, 2000
CVE Published
05:00 AM
Jan 22, 2001
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-1050?
CVE-2000-1050 is classified as a high-severity vulnerability due to its potential to expose sensitive files.
2
How do I fix CVE-2000-1050?
To fix CVE-2000-1050, configure the web server to restrict access to the WEB-INF directory and validate URL inputs.
3
Which software versions are affected by CVE-2000-1050?
CVE-2000-1050 affects Allaire JRun 3.0 and Allaire JRun 3.0 SP1.
4
What type of vulnerability is CVE-2000-1050?
CVE-2000-1050 is an access control vulnerability that allows unauthorized access to restricted directories.
5
Can CVE-2000-1050 be exploited remotely?
Yes, CVE-2000-1050 can be exploited remotely by an attacker who sends a specially crafted URL request.