Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Allaire JRun Unnecessary JSessionID Appending In URL Vulnerability

Allaire JRun is a web application development suite.

When a user visits a web application based on JRun, they are given a session id. Under some circumstances this session id will be appended to the URL requested, despite already being stored in a cookie. This may potentially reveal the session id to a remote web server through a referrer tag.







 

Privacy Statement
Copyright 2009, SecurityFocus