Allaire JRun Web Server Directory...

- AV AC AU C I A
发布: 2001-12-06
修订: 2025-04-13

JRun is a web server implementation distributed by Allaire. JRun does not handle path identifiers correctly, such as the dot-dot-slash (../) identifier, making it possible for a user to escape the web root directory. This vulnerability could be exploited to gather intelligence on a vulnerable host, and could potentially lead to a remote user gaining such information as usernames, system configuration information, or user-owned files that do not have restrictive permissions set.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息