Vulnerabilities > CVE-2000-0629 - Unspecified vulnerability in SUN Java System web Server 1.1.3/2.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
sun
nessus

Summary

The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.

Vulnerable Configurations

Part Description Count
Application
Sun
2

Nessus

NASL familyCGI abuses
NASL idBBOARD.NASL
descriptionThe
last seen2020-06-01
modified2020-06-02
plugin id10507
published2000-09-10
reporterThis script is Copyright (C) 2000-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10507
titleSun Java Web Server bboard Servlet Command Execution