Caucho Technology Resin 2.1.12 - Directory Listings Disclosure
Author: Wang Yun
type: remote
platform: linux
port:
date_added: 2004-02-09
date_updated: 2012-12-25
verified: 1
codes: CVE-2004-0281;OSVDB-6620
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/9617/info
It has been reported that Resin may be prone to an information disclosure vulnerability that may allow an attacker to disclose directory listings by passing malicious data via a URI parameter.
The issue has been reported to present itself on Windows NT/2000 systems running Apache 1.3.29 and Resin 2.1.12.
http://www.example.com/WEB-INF../