CVE-2001-1511: Medium severity Macromedia JRun vulnerability
JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote attackers to read arbitrary JavaServer Pages (JSP) source code via a request URL containing the source filename ending in (1) "jsp%00" or (2) "js%2570".
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1511?
CVE-2001-1511 is considered to have a high severity due to its ability to allow remote attackers to read arbitrary JSP source code.
How do I fix CVE-2001-1511?
To fix CVE-2001-1511, upgrade JRun to a version that does not exhibit this vulnerability or implement proper access controls to restrict file access.
What versions of JRun are affected by CVE-2001-1511?
CVE-2001-1511 affects JRun versions 3.0 and 3.1 running on JRun Web Server and IIS.
What is the impact of CVE-2001-1511 on JRun servers?
The impact of CVE-2001-1511 on JRun servers is that attackers can gain unauthorized access to sensitive JSP source code.
Can CVE-2001-1511 be exploited remotely?
Yes, CVE-2001-1511 can be exploited remotely by attackers through crafted request URLs.