VYPR
Unrated severityNVD Advisory· Published Oct 4, 2002· Updated Apr 16, 2026

CVE-2002-1025

CVE-2002-1025

Description

JRun 3.0 through 4.0 allows remote attackers to read JSP source code via an encoded null byte in an HTTP GET request, which causes the server to send the .JSP file unparsed.

Affected products

3
  • Macromedia/Jrun3 versions
    cpe:2.3:a:macromedia:jrun:3.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:macromedia:jrun:3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:macromedia:jrun:3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:macromedia:jrun:4.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.