Unrestricted Access and Arbitrary Command Execution in eWave ServletExec 3.0C and Earlier

Unrestricted Access and Arbitrary Command Execution in eWave ServletExec 3.0C and Earlier

CVE-2000-1024 · HIGH Severity

AV:N/AC:L/AU:N/C:C/I:C/A:C

eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands.

Learn more about our Web Application Penetration Testing UK.