CVE-2000-1050
Allaire JRun 3.0 - Unauthenticated Directory Traversal via Extra Leading Slash
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2000-1050. PoCs published by Foundstone Labs.
AI-analyzed exploit summary This is a writeup describing a directory traversal vulnerability in Allaire JRun that allows remote attackers to view the contents of the WEB-INF directory by sending a malformed URL with an additional '/'. The issue persists when using raw HTTP GET requests via Microsoft IIS connectors.
Description
Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra "/" in the beginning of the request (aka the "extra leading slash").
Exploits (1)
This is a writeup describing a directory traversal vulnerability in Allaire JRun that allows remote attackers to view the contents of the WEB-INF directory by sending a malformed URL with an additional '/'. The issue persists when using raw HTTP GET requests via Microsoft IIS connectors.