5
CVSSv2

CVE-2000-0500

Published: 21/06/2000 Updated: 10/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The default configuration of BEA WebLogic 5.1.0 allows a remote malicious user to view source code of programs by requesting a URL beginning with /file/, which causes the default servlet to display the file without further processing.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bea weblogic server 5.1

bea weblogic server 4.0

bea weblogic server 3.1.8

bea weblogic server 4.5

Exploits

source: wwwsecurityfocuscom/bid/1378/info Within WebLogic Server and WebLogic Express there are four main java servlets registered to serve different kind of files A default servlet exists if a requested file does not have an assigned servlet If an http request is made that includes "/file/", the server calls upon the default servlet w ...