Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing '/' (slash), as demonstrated using ctx.
Link | Tags |
---|---|
http://www.macromedia.com/v1/handlers/index.cfm?ID=22260&Method=Full | patch vendor advisory |
http://www.iss.net/security_center/static/7680.php | vdb entry patch |
http://www.securityfocus.com/bid/3600 | vdb entry |