Secunia Reports Cross-Site Scripting Vulnerability in JRun

 
Dec 02, 2003

Secunia Advisories reported that some vulnerabilities have been identified in Macromedia JRun, which can be exploited by malicious people to conduct Cross-Site Scripting attacks.

The vulnerabilities are caused due to missing input validation in "clusterframe.jsp" and "webserverlist.jsp", which are accessible via the JMC interface. This can be exploited to execute arbitrary script code in a user's browser session by tricking the user into visiting a malicious website or clicking a specially crafted link.

To find out more, see the Secunia Advisory below:

Macromedia JRun JMC Interface Cross-Site Scripting Vulnerabilities (Secunia Advisories, November 28, 2003)

Add a Comment
(If you subscribe, any new posts to this thread will be sent to your email address.)
  
Privacy | FAQ | Site Map | About | Guidelines | Contact | Advertising | What is ColdFusion?
House of Fusion | ColdFusion Jobs | Blog of Fusion | AHP Hosting