Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2000-0629

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2000-0629
Last Modified 10 Sep 2008 03:05:28
Published 12 Jul 2000 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2000-0629

Summary

The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.

Vulnerable Systems

Application

  • Sun Java System Web Server 1.1.3

  • Sun Java System Web Server 2.0


References

MISC - http://www.sun.com/software/jwebserver/faq/jwsca-2000-02.html

BUGTRAQ - 20000711 Sun's Java Web Server remote command execution vulnerability

BID - 1459


Last Updated: 27 May 2016 10:35:48