CVE-2001-0098

WebLogic Server < 4.5.2 - Remote Code Execution via Long URL with Dot-Dot Sequence

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-0098. PoCs published by peter.grundl.

AI-analyzed exploit summary The provided text describes a buffer overflow vulnerability in BEA Systems WebLogic Server triggered by URL requests starting with two dots (..) followed by an overly long string. This could lead to a crash or arbitrary code execution in the context of the web server.

Description

Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string.

Exploits (1)

exploitdb WRITEUP VERIFIED
by peter.grundl · textremotemultiple
https://www.exploit-db.com/exploits/20516

The provided text describes a buffer overflow vulnerability in BEA Systems WebLogic Server triggered by URL requests starting with two dots (..) followed by an overly long string. This could lead to a crash or arbitrary code execution in the context of the web server.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: BEA Systems WebLogic Server
No auth needed
Prerequisites: Network access to the WebLogic Server · Ability to send crafted HTTP requests
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2138
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5782
Exploit, Patch mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-12/0331.html

Scores

EPSS 0.7837
EPSS Percentile 99.5%

Details

Status published
Products (1)
bea/weblogic_server < 4.5.2
Published Feb 12, 2001
Tracked Since Feb 18, 2026