eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/5450 | vdb entry |
http://www.securityfocus.com/bid/1876 | patch vendor advisory vdb entry |
http://marc.info/?l=bugtraq&m=97306581513537&w=2 | mailing list |