WHIR | BLOGS | WEB HOST NEWS | FIND WEB HOSTS | RESELLER HOSTING | MAGAZINE | WHIR TV | NEWSLETTER | rss feeds
web hosting news - daily web host interviews, insight Jobs | Events | Sitemap | Search
Green Data Center Info


WEB HOSTING NEWS | BLOGS | INTERVIEWS | EUROPE | EVENTS | WEB HOSTING JOBS

<< The Web Host Industry Week in Review     VeriCenter Launches Recovery Tools >>


Vulnerabilities Found in JRun Server

September 24, 2004 -- (WEB HOST INDUSTRY REVIEW) -- According to a advisory from security researcher Secunia (secunia.com) vulnerabilities in Macromedia's JRun Web application server could allow a remote attacker to compromise a machine running the software.

   
Level 1 PCI DSS Certified Service Provider! DataPipe delivers the best network & support; top tier data centers; New York metro, Silicon Valley, London, Hong Kong, Shanghai. DataPipe - Personal Touch, Global Reach.

The "moderately critical" vulnerabilities, affecting versions 3.0, 3.1 and 4.0, said the advisory, could be exploited to hijack an authenticated user's session, conduct cross-site scripting attacks, disclose sensitive information and initiate a denial of service attack.

Specific vulnerabilities include: an implementation error in the generation of handling of JSESSIONIDs, which can be exploited to hijack a user session; a cross-site scripting and session handling vulnerability in the JRun Management Console, which can be used to execute arbitrary HTML and script code in a user's browser session, or hijack a user's session; a URL parsing error, limited to the Microsoft IIS connector, which can be exploited to show the source of script files and other files; and a boundary error in the verbose logging module that can be used to crash the Web server.

Secunia recommends that users apply patches released by Macromedia.

Print this Page       Email this Page        Add to: | del.icio.us | digg



Q&A: Paul Hirsch, AIHSP

Q9 Moves Forward Amid Acquisition

Mailtrust Blooms Under Rackspace

Q&A: Tucows Marketing VP Ken Schafer

Q&A: Maria Farnon, Level 3 VP

Outsourced, Not Offshore in Mexico

Q&A: Mosso Uptime Chief Bruce Runyan

More feature interviews and reports
 

Asymmetry of Information

Applications and the law

Rackspace to Review Results

Interview Notes: Patrick Matthews and Kirk Averett of Mailtrust

TrendPoint's Four-Point "Green Data Center" Plan

Video Interview with Dan Ushman, SingleHop

More posts from our Bloggers


Major Internet Outages

Weta Digital Builds NZ Facility

DataChambers Expands NC Facility

Web Traffic Grows 53%, Capacity More

Replace 3 Year Servers, says Memset

Gomez Adds Testing For Chrome, IE 8

Internap Delivers CDN for Round Table

The Web Host Industry Week in Review

Comcast Appeals FCC Ruling

IRS Taxed By Unauthorized Servers

Server Intellect Debuts MS SQL 08

Secure64 Gains $3.7M In Funding


 

 

SPONSORED LINKS
> Apollo Hosting: Award Winning Website Hosting from $6.96 – Click Here!

> iWeb: Quality servers. 3000GB of traffic for only $69

> TopLayer: SC Mag Recommended. Protect against DDoS Attacks & more.

> Parallels: Automation and Virtualization. Buy ONLINE or Learn MORE!

> Website Source: Powerful Website hosting starting at $6.85

> Rackspace: Hosting Solutions Built to Your Needs

> GeoTrust: The Most Flexible SSL Partner Program

> The Planet: Dedicated servers and managed hosting solutions

> Sell More Services with Microsoft Services Provider Licensing!

> SERVER4YOU: Dedicated servers – starting $29!

WHIR NEWSLETTER SIGN-UP | MANAGE SUBSCRIPTIONS | WHIR RSS FEEDS
Name:
Email:
Password:
theWHIR Blog Email Update
Magazine
Daily News
Find Web Hosts
Occupation:
Company Type:

Find Web Hosts | Reseller Hosting | Personal Web Hosting | Small Business Web Hosting | Dedicated Servers | Managed Hosting | Adult Web Hosting


About WHIR | Online Advertising | Print Advertising | Print Subscription | Email Newsletters | RSS Feeds
 
Submit News | Privacy Policy | Buy Reprints

Web Host Industry Review, Inc. is not responsible for the content of comments submitted by our users.

  © Copyright Web Host Industry Review, Inc.