Caucho Technology Resin Server Example Servlet Path Disclosure Vulnerability
BID:5095
Info
Caucho Technology Resin Server Example Servlet Path Disclosure Vulnerability
| Bugtraq ID: | 5095 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2002 12:00AM |
| Updated: | Jun 25 2002 12:00AM |
| Credit: | Discovered by [email protected]. |
| Vulnerable: |
Caucho Resin 2.1.2 Caucho Resin 2.1.1 Caucho Resin 2.0 |
| Not Vulnerable: | |
Discussion
Caucho Technology Resin Server Example Servlet Path Disclosure Vulnerability
A vulnerability has been reported in Resin Server, deployed on a Microsoft Windows platform, that may allow remote attackers to view sensitive path information.
Caucho Technology's Resin ships with a number of servlets which may reveal the absolute path of the servlet installation when requested via HTTP.
This information will give the attacker filesystem structure information of the host running Resin.
This issue has been reported in Resin 2.0.5 - 2.1.2.
A vulnerability has been reported in Resin Server, deployed on a Microsoft Windows platform, that may allow remote attackers to view sensitive path information.
Caucho Technology's Resin ships with a number of servlets which may reveal the absolute path of the servlet installation when requested via HTTP.
This information will give the attacker filesystem structure information of the host running Resin.
This issue has been reported in Resin 2.0.5 - 2.1.2.
Exploit / POC
Caucho Technology Resin Server Example Servlet Path Disclosure Vulnerability
No exploit required.
No exploit required.
Solution / Fix
Caucho Technology Resin Server Example Servlet Path Disclosure Vulnerability
Solution:
Original Guru <[email protected]> has suggested to remove the \examples\ directory.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Original Guru <[email protected]> has suggested to remove the \examples\ directory.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Caucho Technology Resin Server Example Servlet Path Disclosure Vulnerability
References:
References:
- Caucho Technology Homepage (Caucho Technology)