CVE-2001-1084

Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error message.

Scoring

CVSS base score
0.01
EPSS probability
0.16%
Published
2002-06-25
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs