Vulnerabilities > CVE-2000-0685 - Unspecified vulnerability in BEA Weblogic Server 3.1.8/4.0.4/4.5.1

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
bea
critical
exploit available

Summary

BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.

Vulnerable Configurations

Part Description Count
Application
Bea
3

Exploit-Db

descriptionWeblogic 3.1.8/4.0.4/4.5.1 Remote Command Execution. CVE-2000-0685. Remote exploit for windows platform
idEDB-ID:20125
last seen2016-02-02
modified2000-08-01
published2000-08-01
reporterFoundstone Inc.
sourcehttps://www.exploit-db.com/download/20125/
titleWeblogic 3.1.8/4.0.4/4.5.1 - Remote Command Execution