First published: Fri Dec 31 2004(Updated: )
Cross-site scripting (XSS) vulnerability in the Management Console in JRun 4.0 allows remote attackers to execute arbitrary web script or HTML and possibly hijack a user's session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe JRun | =3.0 | |
Adobe JRun | =3.1 | |
Adobe JRun | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1477 is considered a high-severity vulnerability due to its potential for remote exploitation via XSS.
To fix CVE-2004-1477, users should upgrade JRun to version 4.0.1 or later, or apply the relevant security patches provided by Macromedia.
CVE-2004-1477 affects JRun versions 3.0, 3.1, and 4.0.
Yes, CVE-2004-1477 can potentially allow session hijacking due to its cross-site scripting capabilities.
CVE-2004-1477 is associated with cross-site scripting (XSS) attacks.