Macromedia.JRun.Server.File.Disclosure

description-logoDescription

This indicates a possible attempt to exploit a file disclosure vulnerability in Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE. The vulnerability allows remote attackers to bypass authentication and view source files, such as .asp, .pl, and .php files.

affected-products-logoAffected Products

The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE.

Impact logoImpact

Source code disclosure.

recomended-action-logoRecommended Actions

Apply patches.
JRun 3.0 / 3.1:
See the original vendor advisory
JRun 4.0:
http://www.macromedia.com/support/jrun/updaters.html

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)