CVE-2008-2405
https://notcve.org/view.php?id=CVE-2008-2405
Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in HTTP requests to unspecified ASP applications. Sun Java Active Server Pages (ASP) Server anterior a 4.0.3, permite a atacantes remotos ejecutar comandos de su elección a través de metacaractéres en la consola en una petición HTTP hacia una aplicación ASP sin especificar. • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=709 http://secunia.com/advisories/30523 http://sunsolve.sun.com/search/document.do?assetkey=1-66-238184-1 http://www.securitytracker.com/id?1020190 http://www.vupen.com/english/advisories/2008/1742/references https://exchange.xforce.ibmcloud.com/vulnerabilities/42829 • CWE-20: Improper Input Validation •
CVE-2008-2401
https://notcve.org/view.php?id=CVE-2008-2401
The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to append to arbitrary new or existing files via the first argument to a certain file that is included by multiple unspecified ASP applications. EL Admin Server en Sun Java Active Server Pages (ASP) Server anterior a 4.0.3, permite a atacantes remotos añadir (información, contenido,etc) a ficheros nuevos de su elección o a los ya existentes, a través del primer argumento en cierto fichero que es incluido por multitud de aplicaciones ASP sin especificar. • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=705 http://secunia.com/advisories/30523 http://sunsolve.sun.com/search/document.do?assetkey=1-66-238184-1 http://www.securitytracker.com/id?1020186 http://www.vupen.com/english/advisories/2008/1742/references https://exchange.xforce.ibmcloud.com/vulnerabilities/42832 • CWE-20: Improper Input Validation •