← לוח פגיעויות

CVE-2000-1050

טרם דורגה

טרם דורג — בהתאם למדיניות NVD מאפריל 2026, רוב ה-CVE אינם מנותחים מיידית. ציון EPSS (אם קיים) עדיין מוצג.

תיאור (מקור, אנגלית)

Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra "/" in the beginning of the request (aka the "extra leading slash").

מדדים

EPSS — סבירות ניצול
8% (אחוזון 100) נכון ל-23/9/2026

מוצרים מושפעים

macromedia: jrun

קישורים