Skip to main content

Vendor/product archive

caucho_technology / resin CVEs

Beta · best-effort

17 CVEs tagged to caucho_technology / resin1 Critical, 1 High, 15 Medium, 0 Low, 0 Unrated.

CVE-2007-2439

Published May 16, 2007

Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to cause a denial of service (device hang) and read data from a COM or LPT d…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-2440

Published May 16, 2007

Directory traversal vulnerability in Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to read certain files via a .. (dot dot…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2441

Published May 16, 2007

Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to obtain the system path via certain URLs associated with (1) deploying web…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1953

Published May 17, 2006

Directory traversal vulnerability in Caucho Resin 3.0.17 and 3.0.18 for Windows allows remote attackers to read arbitrary files via a "C:%5C" (encoded drive letter) in a URL.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2437

Published May 17, 2006

The viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to obtain the source code for file under the web root via…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2438

Published May 17, 2006

Directory traversal vulnerability in the viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to read arbitrary fil…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0280

Published Nov 23, 2004

Caucho Technology Resin 2.1.12 allows remote attackers to view JSP source via an HTTP request to a .jsp file that ends in a "%20" (encoded space character), e.g. index.jsp%20.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1513

Published Dec 31, 2003

Multiple cross-site scripting (XSS) vulnerabilities in example scripts in Caucho Technology Resin 2.0 through 2.1.2 allow remote attackers to inject arbitrary web script or HTML v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1987

Published Dec 31, 2002

Directory traversal vulnerability in view_source.jsp in Resin 2.1.2 allows remote attackers to read arbitrary files via a "\.." (backslash dot dot).

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1988

Published Dec 31, 2002

Resin 2.1.1 allows remote attackers to cause a denial of service (memory consumption and hang) via a URL with long variables for non-existent resources.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1989

Published Dec 31, 2002

Resin 2.1.1 allows remote attackers to cause a denial of service (thread and connection consumption) via multiple URL requests containing the DOS 'CON' device name and a registere…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1990

Published Dec 31, 2002

Resin 2.0.5 through 2.1.2 allows remote attackers to reveal physical path information via a URL request for the example Java class file HelloServlet.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2090

Published Dec 31, 2002

Caucho Technology Resin server 2.1.1 to 2.1.2 allows remote attackers to obtain server's root path via requests for MS-DOS device names such as lpt9.xtp.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0828

Published Dec 6, 2001

A cross-site scripting vulnerability in Caucho Technology Resin before 1.2.4 allows a malicious webmaster to embed Javascript in a hyperlink that ends in a .jsp extension, which c…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0399

Published Jun 18, 2001

Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0304

Published May 3, 2001

Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1224

Published Nov 23, 2000

Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1