First published: Mon Dec 11 2000(Updated: )
eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Unify eWave ServletExec | =3.0c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1024 is classified as a high severity vulnerability due to the potential for remote code execution.
To mitigate CVE-2000-1024, upgrade to a version of eWave ServletExec that is not affected, or implement access controls to restrict access to the UploadServlet.
If exploited, CVE-2000-1024 allows attackers to upload arbitrary files and execute commands, potentially leading to complete system compromise.
CVE-2000-1024 affects eWave ServletExec versions 3.0C and earlier.
Organizations using eWave ServletExec 3.0C and earlier are vulnerable to CVE-2000-1024.