The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.
| Software | From | Fixed in |
|---|---|---|
| sun / java_system_web_server | 1.1_beta | 1.1_beta.x |
| sun / java_system_web_server | 1.1.3 | 1.1.3.x |
| sun / java_system_web_server | 2.0 | 2.0.x |
| sun / java_system_web_server | 1.1.2 | 1.1.2.x |