CVE-2008-2405: Input Validation
Published Jun 4, 2008
·Updated
Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in HTTP requests to unspecified ASP applications.
Affected Software
3 affected components
Sun Java Active Server Pages=4.0.1
Sun Java Active Server Pages<=4.0.2
Sun Java Active Server Pages=4.0.0
Event History
Jun 4, 2008
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2405?
CVE-2008-2405 is classified as a critical vulnerability due to the potential for remote command execution.
2
How do I fix CVE-2008-2405?
To remediate CVE-2008-2405, upgrade to Sun Java Active Server Pages version 4.0.3 or later.
3
What software is affected by CVE-2008-2405?
CVE-2008-2405 affects Sun Java Active Server Pages versions 4.0.1, 4.0.2, and 4.0.0.
4
What kind of attacks can exploit CVE-2008-2405?
CVE-2008-2405 can be exploited by attackers to execute arbitrary commands on the server.
5
Is there a workaround for CVE-2008-2405 if I cannot upgrade?
Implementing strict input validation and filtering can act as a temporary workaround for CVE-2008-2405.