Description
The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.
Affected products
- sun / java_system_web_server1.1.2 – 1.1.2
- sun / java_system_web_server1.1.3 – 1.1.3
- sun / java_system_web_server1.1_beta – 1.1_beta
- sun / java_system_web_server2.0 – 2.0