CVE-2004-1477: XSS
Published Dec 31, 2004
·Updated
Cross-site scripting (XSS) vulnerability in the Management Console in JRun 4.0 allows remote attackers to execute arbitrary web script or HTML and possibly hijack a user's session.
Affected Software
3 affected components
Macromedia JRun=3.0
Macromedia JRun=3.1
Macromedia JRun=4.0
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 13, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1477?
CVE-2004-1477 is considered a high-severity vulnerability due to its potential for remote exploitation via XSS.
2
How do I fix CVE-2004-1477?
To fix CVE-2004-1477, users should upgrade JRun to version 4.0.1 or later, or apply the relevant security patches provided by Macromedia.
3
Which versions of JRun are affected by CVE-2004-1477?
CVE-2004-1477 affects JRun versions 3.0, 3.1, and 4.0.
4
Can CVE-2004-1477 allow session hijacking?
Yes, CVE-2004-1477 can potentially allow session hijacking due to its cross-site scripting capabilities.
5
What type of attack is associated with CVE-2004-1477?
CVE-2004-1477 is associated with cross-site scripting (XSS) attacks.