First published: Wed Jun 04 2008(Updated: )
The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to append to arbitrary new or existing files via the first argument to a certain file that is included by multiple unspecified ASP applications.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java Active Server | =4.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2401 is classified as a medium severity vulnerability due to its potential for file manipulation by remote attackers.
To fix CVE-2008-2401, it is recommended to upgrade Sun Java Active Server to version 4.0.3 or later.
CVE-2008-2401 is a file inclusion vulnerability that allows remote attackers to append data to files.
CVE-2008-2401 affects users of Sun Java Active Server version 4.0.2.
Yes, CVE-2008-2401 can be exploited remotely by attackers targeting the vulnerable version of Sun Java Active Server.