Sun Java ASP Server File Creation Remote Code Execution Vulnerability
BID:29542
Info
Sun Java ASP Server File Creation Remote Code Execution Vulnerability
| Bugtraq ID: | 29542 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2401 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 04 2008 12:00AM |
| Updated: | Jun 04 2008 12:00AM |
| Credit: | anonymous |
| Vulnerable: |
Sun Java System Active Server Pages (ASP) Server 4.0.2 Sun Java System Active Server Pages (ASP) Server 4.0.1 Sun Java System Active Server Pages (ASP) Server 4.0 |
| Not Vulnerable: |
Sun Java System Active Server Pages (ASP) Server 4.0.3 |
Discussion
Sun Java ASP Server File Creation Remote Code Execution Vulnerability
Sun Java ASP Server is prone to a remote code-execution vulnerability because of a file-creation issue.
An attacker can exploit this issue to execute arbitrary code with superuser privileges. Successfully exploiting this issue will result in the complete compromise of affected computers.
Versions prior to Sun Java ASP Server 4.0.3 are vulnerable.
Sun Java ASP Server is prone to a remote code-execution vulnerability because of a file-creation issue.
An attacker can exploit this issue to execute arbitrary code with superuser privileges. Successfully exploiting this issue will result in the complete compromise of affected computers.
Versions prior to Sun Java ASP Server 4.0.3 are vulnerable.
Exploit / POC
Sun Java ASP Server File Creation Remote Code Execution Vulnerability
An attacker can use a browser to exploit this issue.
An attacker can use a browser to exploit this issue.
Solution / Fix
Sun Java ASP Server File Creation Remote Code Execution Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Solution:
The vendor has released fixes. Please see the references for more information.
References
Sun Java ASP Server File Creation Remote Code Execution Vulnerability
References:
References: