Vulnerabilities > CVE-2000-0684 - Unspecified vulnerability in BEA Weblogic Server 3.1.8/4.0.4/4.5.1

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
bea
critical
exploit available

Summary

BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.

Vulnerable Configurations

Part Description Count
Application
Bea
3

Exploit-Db

descriptionNetZero ZeroPort 3.0 Weak Encryption Method Vulnerability. CVE-2000-0625,CVE-2000-0684. Local exploit for windows platform
idEDB-ID:20081
last seen2016-02-02
modified2000-07-18
published2000-07-18
reporterBrian Carrier
sourcehttps://www.exploit-db.com/download/20081/
titleNetZero ZeroPort 3.0 Weak Encryption Method Vulnerability