10

CVE-2000-1053

Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack and directly calling the com.livesoftware.jrun.plugins.JSP JSP servlet.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Macromedia ≫ Jrun Version 2.3.x
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.58% 0.953
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=97236125107957&w=2
http://www.allaire.com/handlers/index.cfm?ID=17969&Method=Full
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/5406