Record summary

CVE-2000-0685 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.

Description

BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBWeblogic 3.1.8/4.0.4/4.5.1 - Remote Command ExecutionExploitDB exploitby Foundstone Inc.Not analyzed1 file
ExploitDB

PoC details

References

4