Vulnerabilities > CVE-2001-0098 - Unspecified vulnerability in BEA Weblogic Server 4.5.2
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | BEA Systems Weblogic Server 4.0 x/4.5 x/5.1 x Double Dot Buffer Overflow. CVE-2001-0098. Remote exploits for multiple platform |
id | EDB-ID:20516 |
last seen | 2016-02-02 |
modified | 2000-12-19 |
published | 2000-12-19 |
reporter | peter.grundl |
source | https://www.exploit-db.com/download/20516/ |
title | BEA Systems Weblogic Server 4.0 x/4.5 x/5.1 x Double Dot Buffer Overflow |
Nessus
NASL family | Web Servers |
NASL id | WEBLOGIC_DOTDOTDOS.NASL |
description | Requesting an overly long URL starting with a double dot can crash certain versions of WebLogic servers or possibly even allow for arbitrary code execution. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 10697 |
published | 2001-06-21 |
reporter | This script is Copyright (C) 2001-2018 StrongHoldNet |
source | https://www.tenable.com/plugins/nessus/10697 |
title | WebLogic Server Double Dot GET Request Remote Overflow |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2000-12/0331.html
- http://archives.neohapsis.com/archives/bugtraq/2000-12/0331.html
- http://www.securityfocus.com/bid/2138
- http://www.securityfocus.com/bid/2138
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5782
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5782