Caucho Resin Viewfile Information Disclosure Vulnerability
BID:18007
CVE-2006-2437 | CVE-2006-2438 |Info
Caucho Resin Viewfile Information Disclosure Vulnerability
| Bugtraq ID: | 18007 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 16 2006 12:00AM |
| Updated: | May 17 2006 07:59PM |
| Credit: | Joseph Pierini is credited with the discovery of this vulnerability. |
| Vulnerable: |
Caucho Technology Resin 3.0.18 Caucho Technology Resin 3.0.17 |
| Not Vulnerable: |
Caucho Technology Resin 3.0.19 |
Discussion
Caucho Resin Viewfile Information Disclosure Vulnerability
Resin is prone to an information-disclosure vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve the contents of arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.
Resin is prone to an information-disclosure vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve the contents of arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.
Exploit / POC
Caucho Resin Viewfile Information Disclosure Vulnerability
This vulnerability may be exploited with a web client.
The following proof-of-concept URIs are available:
This vulnerability may be exploited with a web client.
The following proof-of-concept URIs are available:
Solution / Fix
Caucho Resin Viewfile Information Disclosure Vulnerability
Solution:
The vendor has released a patch to address this issue; please see the reference section for further details.
Caucho Resin 3.0.17
Caucho Resin 3.0.18
Solution:
The vendor has released a patch to address this issue; please see the reference section for further details.
Caucho Resin 3.0.17
-
Caucho Technology resin-pro-3.0.19.tar.gz
http://www.caucho.com/download/resin-pro-3.0.19.tar.gz
Caucho Resin 3.0.18
-
Caucho Technology resin-pro-3.0.19.tar.gz
http://www.caucho.com/download/resin-pro-3.0.19.tar.gz
References
Caucho Resin Viewfile Information Disclosure Vulnerability
References:
References:
- Caucho Technology Homepage (Caucho Technology)
- Resin Version Updates Announcement (Caucho Technology)
- ScanAlert Security Advisory (Joseph Pierini)