Disclosure Vulnerability in Allaire JRun for Microsoft Internet Information Server
A vulnerability exists in Allaire’s JRun for Microsoft Internet Services (IIS) 5.0 and Internet Information Server (IIS) 4.0 that a remote user can exploit to read any file or directory located within webroot.
December 3, 2001
ReportedNovember 28, 2001, by Defcom Labs.
VERSIONSAFFECTED
Allaire JRun 3.1 and 3.0
DESCRIPTION
Avulnerability exists in Allaire’s JRun for Microsoft Internet Services (IIS)5.0 and Internet Information Server (IIS) 4.0 that a remote user can exploit toread any file or directory located within webroot. By appending the request with“%3f.jsp”, an attacker can read the webroot files.
VENDOR RESPONSE
The vendor, Allaire,released security bulletin MPSB01-13to address this vulnerability and recommends that affected users immediatelyturn off directory browsing of the JRun Default Server for Default Applicationand Demo Application. The bulletin listsseveral other steps that Allaire customers should follow to protect themselvesfrom this vulnerability
CREDIT
Discovered by GeorgeHedfors of Defcom Labs.
Read more about:
MicrosoftAbout the Author
You May Also Like