| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.55382 |
| Category: | CGI abuses |
| Title: | WebLogic Server Multiple Vulnerabilities |
| Summary: | WebLogic Server Multiple Vulnerabilities |
| Description: | The remote host, according to its banner, is running a WebLogic Server vulnerable to multiple vulnerabilities. Known problems include the ability for attackers to poison the web cache, bypass firewall protection, and conduct 'HTTP Request Smuggling' attacks. Version 8.1 SP1 and possibly earlier are vulnerable. Solution : Apply the latest service pack. Risk factor : Medium |
| Cross-Ref: |
BugTraq ID: 13873 Common Vulnerability Exposure (CVE) ID: CVE-2005-2092 Bugtraq: 20050606 A new whitepaper by Watchfire - HTTP Request Smuggling (Google Search) http://seclists.org/lists/bugtraq/2005/Jun/0025.html http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf http://www.securiteam.com/securityreviews/5GP0220G0U.html http://securitytracker.com/id?1014366 XForce ISS Database: bea-weblogic-hrs(42901) http://xforce.iss.net/xforce/xfdb/42901 |
| Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|