VYPR
Unrated severityNVD Advisory· Published Jul 12, 2000· Updated Jun 16, 2026

CVE-2000-0629

CVE-2000-0629

Description

The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.

Affected products

3
  • cpe:2.3:a:sun:java_system_web_server:1.1.3:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:sun:java_system_web_server:1.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:java_system_web_server:2.0:*:*:*:*:*:*:*
    • (no CPE)range: <=2.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.