CVE-2002-0665: Critical severity Macromedia JRun vulnerability
Published Jul 11, 2002
·Updated
Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL.
Affected Software
3 affected components
Macromedia JRun=3.1
Macromedia JRun=3.0
Macromedia JRun=4.0
Event History
Jul 11, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0665?
CVE-2002-0665 is considered a critical vulnerability due to the ability of remote attackers to bypass authentication.
2
How do I fix CVE-2002-0665?
To fix CVE-2002-0665, ensure that the server is updated to a patched version of Macromedia JRun.
3
Which versions of Macromedia JRun are affected by CVE-2002-0665?
CVE-2002-0665 affects Macromedia JRun versions 3.0, 3.1, and 4.0.
4
Can CVE-2002-0665 be exploited remotely?
Yes, CVE-2002-0665 can be exploited remotely, allowing unauthorized access to the JRun Administration Server.
5
Is there a workaround for CVE-2002-0665?
A potential workaround for CVE-2002-0665 is to restrict access to the JRun Administration Server from untrusted networks.