Lucene search

K
cveMitreCVE-2001-1545
HistoryJul 14, 2005 - 4:00 a.m.

CVE-2001-1545

2005-07-1404:00:00
mitre
web.nvd.nist.gov
29
cve-2001-1545
macromedia jrun 3.0
macromedia jrun 3.1
session hijack
jsessionid
cookies

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7

Confidence

Low

EPSS

0.004

Percentile

74.3%

Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers to obtain session IDs and hijack sessions via HTTP referrer fields or sniffing.

Affected configurations

Nvd
Node
macromediajrunMatch3.0
OR
macromediajrunMatch3.1
VendorProductVersionCPE
macromediajrun3.0cpe:2.3:a:macromedia:jrun:3.0:*:*:*:*:*:*:*
macromediajrun3.1cpe:2.3:a:macromedia:jrun:3.1:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7

Confidence

Low

EPSS

0.004

Percentile

74.3%

Related for CVE-2001-1545