Back

CVE-2004-2182

Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information used by the session server.

Published: Dec 31, 2004 Modified: Jun 16, 2026
CWE-287

CVSS Metrics

Affected Products (4)

Vendor Product Version
macromedia jrun 4.0
macromedia jrun 4.0
macromedia jrun 4.0
macromedia jrun 4.0_build_61650

GitHub Security Advisory GHSA-gr3m-3w4f-5p6g

Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.24%

Top 33% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub