CVE-2008-2401: Input Validation
The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to append to arbitrary new or existing files via the first argument to a certain file that is included by multiple unspecified ASP applications.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2401?
CVE-2008-2401 is classified as a medium severity vulnerability due to its potential for file manipulation by remote attackers.
How do I fix CVE-2008-2401?
To fix CVE-2008-2401, it is recommended to upgrade Sun Java Active Server to version 4.0.3 or later.
What type of vulnerability is CVE-2008-2401?
CVE-2008-2401 is a file inclusion vulnerability that allows remote attackers to append data to files.
Who is affected by CVE-2008-2401?
CVE-2008-2401 affects users of Sun Java Active Server version 4.0.2.
Can CVE-2008-2401 be exploited remotely?
Yes, CVE-2008-2401 can be exploited remotely by attackers targeting the vulnerable version of Sun Java Active Server.