Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that contains the "/servlet/" string, which invokes the ServletExec servlet and causes an exception if the servlet is already running.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Unify eWave ServletExec远程拒绝服务攻击漏洞
Vulnerability Description
Unify的eWave ServletExec是一个JSP和Java Servlet引擎,用作流行的web服务器如Apache、IIS、Netscape等的插件。 eWave ServletExec处理异常请求时存在漏洞,远程攻击者可能利用此漏洞对eWave进行拒绝服务攻击。 给ServletExec servlet引擎发送一个URL请求会导致其异常终止。可以通过在URL中加上servlet路径前缀"/servlet"来强制执行任意servlet。在服务器端的类中存在一个名为"ServletExec"的s
CVSS Information
N/A
Vulnerability Type
N/A