VendorsBEAweblogic_server3.1.8
Vulnerabilities

BEA Systems WebLogic 3.1.8

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2008-3257
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request.
Published 2008-07-22 · Modified
10.02 PoCEPSS 0.836
CVE-2000-0684
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.
Published 2000-10-13 · Modified
10.01 PoCEPSS 0.123
CVE-2000-0685
BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.
Published 2000-10-13 · Modified
10.01 PoCEPSS 0.123
CVE-2000-0500
The default configuration of BEA WebLogic 5.1.0 allows a remote attacker to view source code of programs by requesting a URL beginning with /file/, which causes the default servlet to display the file without further processing.
Published 2000-10-13 · Modified
5.01 PoCEPSS 0.046
CVE-2003-0624
Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.
Published 2003-11-05 · Modified
4.31 PoCEPSS 0.038