10
CVSSv2

CVE-2000-0684

Published: 20/10/2000 Updated: 10/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote malicious users to compile and execute Java JSP code by directly invoking the servlet on any source file.

Vulnerable Product Search on Vulmon Subscribe to Product

bea weblogic server 3.1.8

bea weblogic server 4.5.1

bea weblogic server 4.0.4

Exploits

source: wwwsecurityfocuscom/bid/1483/info Netzero is a free internet service provider which requires its users to run the application ZeroPort in order to log onto the network The username and password is stored locally in a text file called iddat and is inadequately encrypted The weakly encrypted username and password may also be stor ...