|
Allaire JRun Unnecessary JSessionID Appending In URL Vulnerability
Allaire JRun is a web application development suite. When a user visits a web application based on JRun, they are given a session id. Under some circumstances this session id will be appended to the URL requested, despite already being stored in a cookie. This may potentially reveal the session id to a remote web server through a referrer tag. |
|
|
Privacy Statement |