CVE-2001-0926
Published Nov 28, 2001
Last updated 7 years ago
Overview
- Description
- SSIFilter in Allaire JRun 3.1, 3.0 and 2.3.3 allows remote attackers to obtain source code for Java server pages (.jsp) and other files in the web root via an HTTP request for a non-existent SSI page, in which the request's body has an #include statement.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:macromedia:jrun:2.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DA955BB7-2B8A-4534-A0F6-AEBD6875EB12" }, { "criteria": "cpe:2.3:a:macromedia:jrun:3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "96D6C1D6-F9AF-4CF0-9F80-AB2C20C7615C" }, { "criteria": "cpe:2.3:a:macromedia:jrun:3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "462BA0C4-D941-4C58-86DF-BF76663723F7" } ], "operator": "OR" } ] } ]