First published: Mon Jul 02 2001(Updated: )
Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe JRun | =2.3.3 | |
Adobe JRun | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1084 is classified as a cross-site scripting vulnerability with a medium severity risk due to potential exploitation by attackers.
To fix CVE-2001-1084, it is recommended to upgrade to a patched version of Allaire JRun that addresses this vulnerability.
CVE-2001-1084 specifically affects Allaire JRun versions 2.3.3 and 3.0.
Attackers can use CVE-2001-1084 to inject malicious JavaScript into error messages displayed by the vulnerable software.
CVE-2001-1084 can be exploited by malicious webmasters who can manipulate error responses to include harmful scripts.