### [CVE-2000-1053](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1053) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack and directly calling the com.livesoftware.jrun.plugins.JSP JSP servlet. ### POC #### Reference - http://marc.info/?l=bugtraq&m=97236125107957&w=2 - http://marc.info/?l=bugtraq&m=97236125107957&w=2 #### Github - https://github.com/octane23/CASE-STUDY-1