Summary
The host is running Adobe JRun and is prone to multiple vulnerabilities.
Impact
Successful exploitation could allow remote attackers to cause XSS attacks or Directory Traversal attack using the affected application.
Impact Level: System/Application
Solution
Apply the security updates.
http://download.macromedia.com/pub/coldfusion/updates/jmc-app.ear
*****
NOTE: Ignore this warning if above mentioned patch is already applied.
*****
Insight
- Multiple XSS vulnerabilities exists due to error in the Management Console which can be exploited to inject arbitrary web script or HTML via unspecified vectors.
- A Directory traversal attack is possible due to error in logging/logviewer.jsp in the Management Console which can be exploited by authenticated users to read arbitrary files via a .. (dot dot) in the logfile parameter.
Affected
Adobe JRun version 4.0 on Windows
References
Severity
Classification
-
CVE CVE-2009-1873, CVE-2009-1874 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities