📦

jrun

Vendor: macromedia

Actively Exploited 0 CISA KEV List
PoC / Exploits 5 Code Available
Total RCEs 0 Remote Access
Total CVEs 68 Total Indexed
Avg. EPSS 3.92% Exploit Prob.
Latest CVE CVE-2009-1874 Aug 18

Security Vulnerability Index

Page 4 / 7
7.5 CVSS

Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error message.

EPSS: 3.11%
5.0 CVSS

Allaire JRun 3.0 allows remote attackers to list contents of the WEB-INF directory, and the web.xml file in the WEB-INF directory, via a malformed URL that contains a "."

EPSS: 1.31%
5.0 CVSS
CVE-2000-1050
Exploit Found

Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra "/" in the beginning of the request (aka the "extra leading slash").

EPSS: 8.18%
10.0 CVSS
CVE-2000-1053
Exploit Found

Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack and directly calling the com.livesoftware.jrun.plugins.JSP JSP servlet.

EPSS: 5.99%
5.0 CVSS

Allaire JRun 2.3 server allows remote attackers to obtain source code for executable content by directly calling the SSIFilter servlet.

EPSS: 1.36%
5.0 CVSS

Directory traversal vulnerability in Allaire JRun 2.3 server allows remote attackers to read arbitrary files via the SSIFilter servlet.

EPSS: 1.92%
5.0 CVSS

Allaire JRun 3.0 http servlet server allows remote attackers to cause a denial of service via a URL that contains a long string of "." characters.

EPSS: 1.71%
5.0 CVSS

JSP sample files in Allaire JRun 2.3.x allow remote attackers to access arbitrary files (e.g. via viewsource.jsp) or obtain configuration information.

EPSS: 2.51%
6.4 CVSS

Servlet examples in Allaire JRun 2.3.x allow remote attackers to obtain sensitive information, e.g. listing HttpSession ID's via the SessionServlet servlet.

EPSS: 1.62%