积极预防 及时发现
快速响应 力保恢复
BEA WebLogic 5.1.x没有完全限制对JSPServlet的访问,这可能导致远程攻击者通...
发布时间:2002-05-20 信息来源:管理员

CNCVE编号:CNCVE-20000684 CVE编号:CVE-2000-0684 安全级别:中 漏洞中文描述: BEA WebLogic 5.1.x没有完全限制对JSPServlet的访问,这可能导致远程攻击者通过直接调用在任何源文件上的servlet来编译和执行Java JSP代码。 漏洞英文描述: BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file. 漏洞参考: 系统类型:其他 漏洞类型:其他