Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

Oracle mod_wl HTTP POST Request Remote Buffer Overflow Vulnerability

Disclosure Date: July 22, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request.
0
Attacker Value
Unknown

CVE-2000-0685

Disclosure Date: October 20, 2000 (last updated February 22, 2025)
BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.
0
Attacker Value
Unknown

CVE-2000-0684

Disclosure Date: October 20, 2000 (last updated February 22, 2025)
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.
0