5
CVE-2001-1545
- EPSS 1.37%
- Veröffentlicht 31.12.2001 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:56:28
- Erkennungen
Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers to obtain session IDs and hijack sessions via HTTP referrer fields or sniffing.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Macromedia ≫ Jrun Version 3.0
Macromedia ≫ Jrun Version 3.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.37% | 0.684 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://www.iss.net/security_center/static/7679.php
http://www.macromedia.com/v1/handlers/index.cfm?ID=22291&Method=Full
http://www.securityfocus.com/bid/3665