Servlet examples in Allaire JRun 2.3.x allow remote attackers to obtain sensitive information, e.g. listing HttpSession IDs via the SessionServlet servlet.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Jrun |
Macromedia |
2.3 (including) |
2.3 (including) |
References