5
CVSSv2

CVE-2000-1224

Published: 23/11/2000 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Caucho Technology Resin 1.2 and possibly earlier allows remote malicious users to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) "..", (2) "%2e..", (3) "%81", (4) "%82", and others.

Vulnerable Product Search on Vulmon Subscribe to Product

caucho technology resin 1.1.5

caucho technology resin 1.2

Exploits

source: wwwsecurityfocuscom/bid/1986/info Resin is a servlet and JSP engine that supports java and javascript ServletExec will return the source code of JSP files when an HTTP request is appended with certain characters This vulnerability is dependent on the platform that Resin is running on Successful exploitation could lead to the ...