Disclosure Vulnerability in Allaire JRun for Microsoft Internet Information Server

A vulnerability exists in Allaire’s JRun for Microsoft Internet Services (IIS) 5.0 and Internet Information Server (IIS) 4.0 that a remote user can exploit to read any file or directory located within webroot.

Ken Pfeil

December 3, 2001

1 Min Read
ITPro Today logo

ReportedNovember 28, 2001, by Defcom Labs.

VERSIONSAFFECTED

  • Allaire JRun 3.1 and 3.0

 

DESCRIPTION
Avulnerability exists in Allaire’s JRun for Microsoft Internet Services (IIS)5.0 and Internet Information Server (IIS) 4.0 that a remote user can exploit toread any file or directory located within webroot. By appending the request with“%3f.jsp”, an attacker can read the webroot files.

 

VENDOR RESPONSE

The vendor, Allaire,released security bulletin MPSB01-13to address this vulnerability and recommends that affected users immediatelyturn off directory browsing of the JRun Default Server for Default Applicationand Demo Application. The bulletin listsseveral other steps that Allaire customers should follow to protect themselvesfrom this vulnerability

 

CREDIT
Discovered by GeorgeHedfors of Defcom Labs.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like