Caucho Technology Resin Server View_Source.JSP Arbitrary File Disclosure Vulnerability
BID:5031
Info
Caucho Technology Resin Server View_Source.JSP Arbitrary File Disclosure Vulnerability
| Bugtraq ID: | 5031 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 17 2002 12:00AM |
| Updated: | Jun 17 2002 12:00AM |
| Credit: | Credited to Peter Gründl ([email protected]). |
| Vulnerable: |
Caucho Resin 2.1.2 |
| Not Vulnerable: | |
Discussion
Caucho Technology Resin Server View_Source.JSP Arbitrary File Disclosure Vulnerability
A vulnerability has been reported in Resin Server, deployed on a Microsoft Windows platform, that may allow remote attackers to view contents of arbitrary files.
The vulnerability occurs when parsing requests for directory traversal. The 'view_source.jsp' script prevents directory traversal via '/../' sequences. However, an attacker attempting directory traversal via '\..\' sequences will succeed. This may allow an attacker to request any files on the vulnerable system readable by the web server.
A vulnerability has been reported in Resin Server, deployed on a Microsoft Windows platform, that may allow remote attackers to view contents of arbitrary files.
The vulnerability occurs when parsing requests for directory traversal. The 'view_source.jsp' script prevents directory traversal via '/../' sequences. However, an attacker attempting directory traversal via '\..\' sequences will succeed. This may allow an attacker to request any files on the vulnerable system readable by the web server.
Exploit / POC
Caucho Technology Resin Server View_Source.JSP Arbitrary File Disclosure Vulnerability
This vulnerability can be exploited with a web browser.
This vulnerability can be exploited with a web browser.
References
Caucho Technology Resin Server View_Source.JSP Arbitrary File Disclosure Vulnerability
References:
References:
- Caucho Technology Homepage (Caucho Technology)