20000731 BEA's WebLogic *.jsp/*.jhtml remote command executionmailing list
http://archives.neohapsis.com/archives/bugtraq/2000-07/0434.html CVE-2000-0685
Weblogic 3.1.8/4.0.4/4.5.1 - Remote Command Execution
Record summary
CVE-2000-0685 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWeblogic 3.1.8/4.0.4/4.5.1 - Remote Command ExecutionExploitDB exploitby Foundstone Inc.Not analyzed1 file
References
4developer.bea.comConfirmation
http://developer.bea.com/alerts/security_000731.html 1525vdb entry
http://www.securityfocus.com/bid/1525 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0685