Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2004-0928 | First vendor Publication | 2004-10-05 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE allows remote attackers to bypass authentication and view source files, such as .asp, .pl, and .php files, via an HTTP request that ends in ";.cfm". |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0928 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 4 | |
Application | 2 | |
Application | 2 | |
Application | 3 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
10240 | Macromedia Multiple Products on IIS Crafted URL Application Source Disclosure JRun contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when a malicious user appends ';.cfm' to the end of a php,asp, or pl file request which bypasses access restrictions and returns the source of the requested file. This flaw may lead to a loss of confidentiality. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Multiple Vendor server file disclosure attempt RuleID : 15990 - Revision : 10 - Type : SERVER-WEBAPP |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2004-09-24 | Name : The remote web application server is affected by multiple flaws. File : jrun_multiple_flaws.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:22:55 |
|
2024-11-28 12:06:14 |
|
2021-05-04 12:02:25 |
|
2021-04-22 01:02:35 |
|
2020-05-23 00:15:54 |
|
2017-07-11 12:01:32 |
|
2016-10-18 12:01:23 |
|
2016-04-26 12:54:13 |
|
2014-02-17 10:28:09 |
|
2014-01-19 21:22:19 |
|
2013-05-11 11:43:21 |
|