Sploitus

CVE-2008-3257

10 known exploits for CVE-2008-3257

Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request.

Bea Weblogic Server
= 3.1.8, 4.0, 4.0.4, 4.5, 4.5.1, 4.5.2, 5.1, 6.0, 6.1, 7.0, 7.0.0.1, 8.1, 9.0, 9.1, 9.2, 10.0
Bea Systems Apache Connector In Weblogic Server
All versions
Bea Systems Weblogic Server
= 10.0_mp1
Oracle Weblogic Server
≤ 10.3
Fix
Available
CVSS 2.0
10.0 HIGH
EPSS
83.6% (100th percentile)
Weakness
CWE-119
NVD status
Modified
Published
2008-07-22
CVE-2008-3257 at NVD
Authoritative description, scoring and affected products

10 known exploits for CVE-2008-3257

Proof-of-concept code and exploit modules indexed by Sploitus