Computer Security
[EN] securityvulns.ru
no-pyccku



Multiple Macromedia JRun bugs
updated since 28.09.2004
Published:15.10.2004
Source:SECUNIA
SecurityVulns ID:4046
Type:remote
Level:7/10
Description:DoS, source code leakage, session hijacking, crossite scripting, buffer overflow.
Affected:MACROMEDIA : JRun 3.0
 MACROMEDIA : JRun 3.1
 ADOBE : JRun 4.0
 MACROMEDIA : ColdFusion MX 6.0
 MACROMEDIA : ColdFusion MX 6.1
CVE:CVE-2006-5860 (Cross-site scripting (XSS) vulnerability in the administrator console for Adobe JRun 4.0, as used in ColdFusion, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.)
Original documentdocumentACROS Security, ACROS Security: Unsanitized Session ID Cookie Allows Modifying Server Response (15.10.2004)
 documentACROS Security, ACROS Security: Session Fixation in JRun Management Console (15.10.2004)
 documentACROS Security, ACROS Security: HTML Injection in JRun Management Console (15.10.2004)
 documentIDEFENSE, [Full-Disclosure] iDEFENSE Security Advisory 10.05.04a: ColdFusion MX 6.1 on IIS File Contents Disclosure (06.10.2004)
 documentEric Lackey, CFMX vulnerability (01.10.2004)
 documentIDEFENSE, [Full-Disclosure] iDEFENSE Security Advisory 09.29.04 - Macromedia JRun 4 mod_jrun Apache Module Buffer Overflow Vulnerability (30.09.2004)
 documentSECUNIA, [SA12647] ColdFusion MX Sensitive Information Disclosure and Denial of Service (28.09.2004)
 documentSECUNIA, [SA12638] Macromedia JRun Server Multiple Vulnerabilities (28.09.2004)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server