First published: Mon Dec 11 2000(Updated: )
Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra "/" in the beginning of the request (aka the "extra leading slash").
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe JRun | =3.0 | |
Adobe JRun | =3.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1050 is classified as a high-severity vulnerability due to its potential to expose sensitive files.
To fix CVE-2000-1050, configure the web server to restrict access to the WEB-INF directory and validate URL inputs.
CVE-2000-1050 affects Allaire JRun 3.0 and Allaire JRun 3.0 SP1.
CVE-2000-1050 is an access control vulnerability that allows unauthorized access to restricted directories.
Yes, CVE-2000-1050 can be exploited remotely by an attacker who sends a specially crafted URL request.