# CVE-2001-1510

## Summary

- **CVE ID:** CVE-2001-1510
- **Severity:** UNKNOWN
- **CVSS Score:** 0.19
- **CWE:** N/A
- **Published:** Jul 14, 2005
- **Last Modified:** Mar 16, 2026

## Description

Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](http://www.iss.net/security_center/static/7623.php)
- [CNA](http://www.securityfocus.com/bid/3592)
- [CNA](http://www.securityfocus.com/archive/1/243636)
- [CNA](http://online.securityfocus.com/archive/1/243203)
- [CNA](http://online.securityfocus.com/archive/1/242843/2002-07-27/2002-08-02/2)
- [CNA](http://www.macromedia.com/v1/handlers/index.cfm?ID=22262&Method=Full)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 3.73%
- **EPSS Percentile:** 87.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._