NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
78941 | CVE-2001-1510 | Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
78942 | CVE-2001-1511 | JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote attackers to read arbitrary JavaServer Pages (JSP) source code via a request URL containing the source filename ending in (1) "jsp%00" or (2) "js%2570". | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
78943 | CVE-2001-1512 | Unknown vulnerability in Allaire JRun 3.1 allows remote attackers to directly access the WEB-INF and META-INF directories and execute arbitrary JavaServer Pages (JSP), a variant of CVE-2000-1050. | 2 | 6.4 | Medium | 2017-01-05 | 2008-09-10 | View | |
78944 | CVE-2001-1513 | Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing "/" (slash), as demonstrated using ctx. | 2 | 7.5 | High | 2017-01-05 | 2008-09-10 | View | |
78945 | CVE-2001-1514 | ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child processes that call the CreateProcess function and are executed with <CFOBJECT> or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account. | 2 | 10 | High | 2017-01-05 | 2008-09-05 | View |
Page 855 of 17672, showing 5 records out of 88360 total, starting on record 4271, ending on 4275