The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Java_system_web_server | Sun | 1.1.2 | 1.1.2 |
Java_system_web_server | Sun | 1.1.3 | 1.1.3 |
Java_system_web_server | Sun | 1.1_beta | 1.1_beta |
Java_system_web_server | Sun | 2.0 | 2.0 |