CVE-2001-1513
Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing ‘/’ (slash), as demonstrated using ctx.
Date published : 2005-07-14
http://www.securityfocus.com/bid/3600
http://www.macromedia.com/v1/handlers/index.cfm?ID=22260&Method=Full