[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2000-0683Date: (C)2000-10-20   (M)2023-12-22


BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /*.shtml/ into the URL, which invokes the SSIServlet.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
OSVDB-1480
BID-1517
http://archives.neohapsis.com/archives/bugtraq/2000-07/0410.html
http://developer.bea.com/alerts/security_000728.html

CPE    13
cpe:/a:bea:weblogic_server:5.1:sp11:express
cpe:/a:bea:weblogic_server:5.1:sp4:express
cpe:/a:bea:weblogic_server:5.1:sp5:express
cpe:/a:bea:weblogic_server:5.1:sp3:express
...

© SecPod Technologies