vendor:
JRun Application Server
by:
Digital Security Research Group [DSecRG]
7,5
CVSS
HIGH
Directory Traversal File Read
22
CWE
Product Name: JRun Application Server
Affected Version From: 4 updater 7
Affected Version To: 4 updater 7
Patch Exists: YES
Related CWE: CVE-2009-1873
CPE: a:adobe:jrun_application_server:4_updater_7
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009
Digital Security Research Group [DSecRG] Advisory #DSECRG-09-052
JRun Management Console Directory Traversal vulnerability. Using Management Console authenticated attacker can read any file on server. Also attacker can exploit this issue using XSS.
Mitigation:
The issue has been solved 17 august 2009. http://www.adobe.com/go/apsb09-12