CVE

Id
4345  
CVE No.
CVE-2001-1545  
Status
Candidate  
Description
Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers to obtain session IDs and hijack sessions via HTTP referrer fields or sniffing.  
Phase
Assigned (20050714)  
Votes
None (candidate not yet proposed)  
Comments