CVE-2001-1544: Medium severity adobe jrun vulnerability
Published Dec 31, 2001
·Updated
Directory traversal vulnerability in Macromedia JRun Web Server (JWS) 2.3.3, 3.0 and 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request.
Affected Software
3 affected components
Macromedia JRun=3.1
Macromedia JRun=2.3.3
Macromedia JRun=3.0
Remediation
Patch Available
Event History
Dec 31, 2001
CVE Published
05:00 AM
Jul 14, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1544?
CVE-2001-1544 is considered a medium-severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2001-1544?
To fix CVE-2001-1544, upgrade Macromedia JRun to the latest version that addresses this vulnerability.
3
What software versions are affected by CVE-2001-1544?
CVE-2001-1544 affects Macromedia JRun versions 2.3.3, 3.0, and 3.1.
4
What type of attack does CVE-2001-1544 allow?
CVE-2001-1544 allows remote attackers to perform directory traversal attacks to read arbitrary files on the server.
5
Can I exploit CVE-2001-1544 without authentication?
Yes, an attacker can exploit CVE-2001-1544 without authentication, making it a significant security risk.