Allaire JRun Cross-Site Scripting...

- AV AC AU C I A
发布: 2001-07-02
修订: 2025-04-13

Allaire JRun is a web application development suite with JSP and Java Servlets. Allaire JRun does not filter script embedding from links that are displayed on a server's website. A malicious webmaster can exploit this vulnerability to cause JavaScript commands or embedded scripts to be executed by any user who clicks on the hyper-link. Upon clicking on the hyper-link, Tomcat will generate an error message including the specified or embedded script. The specified or embedded scripting will be executed in the client's browser and treated as content originating from the target server returning the error message (even though the scripting may have originated at another site entirely).

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息