PT-2000-1563 · Sun · Sun Java Web Server

Publicado

2000-07-12

·

Atualizado

2008-09-10

·

CVE-2000-0629

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sun Java web server versions 2.0 and earlier
Description The default configuration of the Sun Java web server allows remote attackers to execute arbitrary commands. This is achieved by uploading Java code to the server via "board.html", then directly calling the JSP compiler servlet.
Recommendations For Sun Java web server versions 2.0 and earlier, consider disabling the JSP compiler servlet as a temporary workaround until a patch is available. Restrict access to the "board.html" page to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2000-0629

Produtos afetados

Sun Java Web Server