7.5
CVSSv2

CVE-2001-0308

Published: 03/05/2001 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions prior to 0.80, allows remote malicious users to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program.

Vulnerable Product Search on Vulmon Subscribe to Product

bajie java http server

Exploits

source: wwwsecurityfocuscom/bid/2388/info It is possible to execute arbitrary commands on a host running Bajie Webserver A remote user can use Bajie's built-in upload feature to place malicious scripts on Bajie webservers These uploaded scripts are placed in known destination directories and can be automatically executed Unfortunately ...