5
CVSSv2

CVE-2000-1025

Published: 11/12/2000 Updated: 19/12/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

eWave ServletExec JSP/Java servlet engine, versions 3.0C and previous versions, allows remote malicious users to cause a denial of service via a URL that contains the "/servlet/" string, which invokes the ServletExec servlet and causes an exception if the servlet is already running.

Vulnerable Product Search on Vulmon Subscribe to Product

unify ewave servletexec 3.0c

Exploits

source: wwwsecurityfocuscom/bid/1868/info Unify eWave ServletExec is a Java/Java Servlet engine plug-in for major web servers such as Microsoft IIS, Apache, Netscape Enterprise Server, etc eWave ServletExec is susceptible to a denial of service attack if a URL invoking the ServletExec servlet preceded by /servlet is requested The Servl ...