peter bassill · operator
$ cve CVE-2000-1025 JSON

CVE-2000-1025 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 8.5% (pctl 95)

Patch early

A public exploit exists.

Description

eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that contains the "/servlet/" string, which invokes the ServletExec servlet and causes an exception if the servlet is already running.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS8.49% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2000-12-11
Last modified2026-06-16

Affected (1)

VendorProduct
unifyewave servletexec

Public exploits

SourceTitleDate
exploit-dbUnify eWave ServletExec 3.0 c - Denial of Service2000-10-30

References

→ the Explorer  ·  watch your stack  ·  NVD