CVE-2000-0685
high · 10BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.
10
CVSS
12.3%
EPSS (exploit prob.)
96th
EPSS percentile
2000-10-20
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| bea | weblogic_server | 3.1.8 |
| bea | weblogic_server | 4.0.4 |
| bea | weblogic_server | 4.5.1 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/bugtraq/2000-07/0434.html
- http://developer.bea.com/alerts/security_000731.html
- http://www.securityfocus.com/bid/1525
- http://archives.neohapsis.com/archives/bugtraq/2000-07/0434.html
- http://developer.bea.com/alerts/security_000731.html
- http://www.securityfocus.com/bid/1525
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2000-0685