CVE Vulnerabilities

CVE-2000-0812

Published: Nov 14, 2000 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.

Affected Software

Name Vendor Start Version End Version
Java_system_web_server Sun 1.1.2 (including) 1.1.2 (including)
Java_system_web_server Sun 1.1.3 (including) 1.1.3 (including)
Java_system_web_server Sun 1.1_beta (including) 1.1_beta (including)
Java_system_web_server Sun 2.0 (including) 2.0 (including)

References