Vulnerability Name: | CVE-2000-0629 (CCN-5135) | ||||||||
Assigned: | 2000-07-12 | ||||||||
Published: | 2000-07-12 | ||||||||
Updated: | 2008-09-10 | ||||||||
Summary: | The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: BUGTRAQ Type: Exploit, Patch, Vendor Advisory 20000711 Sun's Java Web Server remote command execution vulnerability Source: CCN Type: Sun Microsystems, Inc. Security Bulletin #00197 Java Web Server Source: MITRE Type: CNA CVE-2000-0629 Source: MITRE Type: CNA CVE-2000-0812 Source: CCN Type: CIAC Information Bulletin L-033 Sun Java Web Server Vulnerability Source: CCN Type: Foundstone Security Advisory FS-082200-11-JWS Sun's Java Web Server Remote Command Execution on Admin Server Source: CCN Type: OSVDB ID: 10880 Sun Java Web Server com.sun.server.http.pagecompile.jsp92.JspServlet Arbitrary Code Execution Source: CCN Type: OSVDB ID: 406 Sun Java Web Server bboard Servlet Command Execution Source: BID Type: UNKNOWN 1459 Source: CCN Type: BID-1459 Sun Java Web Server Vulnerability Source: CCN Type: BID-1600 Sun Java Web Server Web Admin / Bullettin Board Vulnerability Source: CCN Type: Sun FAQ page Java Web Server: CERT Advisory CA-2000-02 Source: MISC Type: Patch, Vendor Advisory http://www.sun.com/software/jwebserver/faq/jwsca-2000-02.html Source: XF Type: UNKNOWN sunjava-webadmin-bbs(5135) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |