CVE Vulnerabilities

CVE-2000-0812

Published: Nov 14, 2000 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.

Affected Software

NameVendorStart VersionEnd Version
Java_system_web_serverSun1.1.2 (including)1.1.2 (including)
Java_system_web_serverSun1.1.3 (including)1.1.3 (including)
Java_system_web_serverSun1.1_beta (including)1.1_beta (including)
Java_system_web_serverSun2.0 (including)2.0 (including)

References