VYPR
Unrated severityNVD Advisory· Published Jul 12, 2000· Updated Apr 16, 2026

CVE-2000-0629

CVE-2000-0629

Description

The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.

Affected products

2
  • cpe:2.3:a:sun:java_system_web_server:1.1.3:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sun:java_system_web_server:1.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:java_system_web_server:2.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.