CVE

Id
4310  
CVE No.
CVE-2001-1510  
Status
Candidate  
Description
Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL.  
Phase
Assigned (20050714)  
Votes
None (candidate not yet proposed)  
Comments