BEA WebLogic Server Double Dot缓冲区溢出漏洞

漏洞信息详情

BEA WebLogic Server Double Dot缓冲区溢出漏洞

漏洞简介

Bea WebLogic Server 5.1.0版本存在缓冲区溢出漏洞。远程攻击者借助超长的以“..”字符串开始的URL执行任意命令。

漏洞公告

BEA Systems has released WebLogic Server 5.1 SP 7 which is not susceptible to this vulnerability. It is available for download at the following location:
http://commerce.beasys.com/downloads/weblogic_server.jsp

参考网址

来源: XF
名称: weblogic-dot-bo
链接:http://xforce.iss.net/static/5782.php

来源: BID
名称: 2138
链接:http://www.securityfocus.com/bid/2138

来源: BUGTRAQ
名称: 20001219 def-2000-04: Bea WebLogic Server dotdot-overflow
链接:http://archives.neohapsis.com/archives/bugtraq/2000-12/0331.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享