CVE-2000-1053
high · 10Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack and directly calling the com.livesoftware.jrun.plugins.JSP JSP servlet.
10
CVSS
10.6%
EPSS (exploit prob.)
96th
EPSS percentile
2000-12-11
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| macromedia | jrun | 2.3.x |
Check a specific version with /api/v1/cve/match.
References
- http://marc.info/?l=bugtraq&m=97236125107957&w=2
- http://www.allaire.com/handlers/index.cfm?ID=17969&Method=Full
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5406
- http://marc.info/?l=bugtraq&m=97236125107957&w=2
- http://www.allaire.com/handlers/index.cfm?ID=17969&Method=Full
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5406
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2000-1053