20001023 Allaire JRUN 2.3 Remote command executionmailing list
http://marc.info/?l=bugtraq&m=97236125107957&w=2 CVE-2000-1053
Allaire JRun 2.3 - Arbitrary Code Execution
Record summary
CVE-2000-1053 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack and directly calling the com.livesoftware.jrun.plugins.JSP JSP servlet.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAllaire JRun 2.3 - Arbitrary Code ExecutionExploitDB exploitby Foundstone LabsNot analyzed1 file
References
4ASB00-029Vendor advisory
http://www.allaire.com/handlers/index.cfm?ID=17969&Method=Full allaire-jrun-jsp-execute(5406)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5406 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-1053