Vulnerabilities > CVE-2000-0500 - Unspecified vulnerability in BEA Weblogic Server

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
bea
exploit available

Summary

The default configuration of BEA WebLogic 5.1.0 allows a remote attacker to view source code of programs by requesting a URL beginning with /file/, which causes the default servlet to display the file without further processing.

Vulnerable Configurations

Part Description Count
Application
Bea
8

Exploit-Db

descriptionBEA Systems WebLogic Express 3.1.8/4/5 Source Code Disclosure. CVE-2000-0500. Remote exploits for multiple platform
idEDB-ID:20027
last seen2016-02-02
modified2000-06-21
published2000-06-21
reporterFoundstone Inc.
sourcehttps://www.exploit-db.com/download/20027/
titleBEA Systems WebLogic Express 3.1.8/4/5 Source Code Disclosure