Vulnerabilities > CVE-2000-1114 - Unspecified vulnerability in Unify Ewave Servletexec 3.0/3.0C

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
unify
exploit available

Summary

Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20".

Vulnerable Configurations

Part Description Count
Application
Unify
2

Exploit-Db

descriptionUnify eWave ServletExec 3 JSP Source Disclosure Vulnerability. CVE-2000-1114. Remote exploit for jsp platform
idEDB-ID:20412
last seen2016-02-02
modified2000-11-21
published2000-11-21
reporterWojciech Woch
sourcehttps://www.exploit-db.com/download/20412/
titleUnify eWave ServletExec 3 JSP Source Disclosure Vulnerability