AI Score
Confidence
Low
EPSS
Percentile
83.4%
Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing ‘/’ (slash), as demonstrated using ctx.
www.iss.net/security_center/static/7680.php
www.macromedia.com/v1/handlers/index.cfm?ID=22260&Method=Full
www.securityfocus.com/bid/3600