    He doesn't need a vuln, he already has access (not that this necessarily gives access). He just needs more information, which I don't have, so I'll just shut up now.
    Does anyone know much about JBoss (http://www.jboss.org/wiki/Wiki.jsp) I found sort of a management console on a band's website and its completely open and hasn't asked me to login or anything. Its all web based, but you access it on port 8080...it just so happened that I was looking for an alternate http server because there's just about nothing on port 80