Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-3257 (weblogic_server, WebLogic Server, apache_connector_in_weblogic_server)

BugsAlert Home > CVE-2008-3257 (weblogic_server, WebLogic Server, apache_connector_in_weblogic_server)
 
 

Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request. NOTE: it is possible that this overlaps CVE-2008-2579 or another issue disclosed in Oracle's CPUJul2008 advisory.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3257

Learn more about CVE-2008-3257 (weblogic_server, WebLogic Server, apache_connector_in_weblogic_server)
 
Tags: cve-2008-3257 weblogic server weblogic server apache connector
 weblogic server

Related Items

      Bugtraq: Re: Joomla 1.0.13 CSRF

      FrSIRT - Sun Java JDK and JRE Code Execution and Security Bypass Issues

      CVE-2008-0992 (Mac OS X, Mac OS X Server)

      Brief: Microsoft patches holes in Office, browser

      FrSIRT - Fedora Security Update Fixes Net-snmp Buffer Overflow and Spoofing

      Astrosoft HelpDesk Multiple XSS

      CVE-2008-2558 (CRE Loaded)

 

Pixel