Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

Oracle mod_wl HTTP POST Request Remote Buffer Overflow Vulnerability

Disclosure Date: July 22, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request.
0
Attacker Value
Unknown

CVE-2003-0624

Disclosure Date: December 01, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.
0
Attacker Value
Unknown

CVE-2000-0685

Disclosure Date: October 20, 2000 (last updated February 22, 2025)
BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.
0
Attacker Value
Unknown

CVE-2000-0684

Disclosure Date: October 20, 2000 (last updated February 22, 2025)
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.
0
Attacker Value
Unknown

CVE-2000-0500

Disclosure Date: June 21, 2000 (last updated February 22, 2025)
The default configuration of BEA WebLogic 5.1.0 allows a remote attacker to view source code of programs by requesting a URL beginning with /file/, which causes the default servlet to display the file without further processing.
0