eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands.
Info
Summary
eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- http://marc.info/?l=bugtraq&m=97306581513537&w=2
- http://www.securityfocus.com/bid/1876 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5450
- http://marc.info/?l=bugtraq&m=97306581513537&w=2
- http://www.securityfocus.com/bid/1876 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5450
Timeline
- nvd_ingest NVD