The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Java_system_web_server | Sun | 1.1.2 (including) | 1.1.2 (including) |
Java_system_web_server | Sun | 1.1.3 (including) | 1.1.3 (including) |
Java_system_web_server | Sun | 1.1_beta (including) | 1.1_beta (including) |
Java_system_web_server | Sun | 2.0 (including) | 2.0 (including) |