5
CVSSv2

CVE-2001-0399

Published: 18/06/2001 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Caucho Resin 1.3b1 and previous versions allows remote malicious users to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request.

Vulnerable Product Search on Vulmon Subscribe to Product

caucho technology resin 1.3

caucho technology resin 1.2

Exploits

source: wwwsecurityfocuscom/bid/2533/info A specially constructed HTTP request could enable a remote attacker to gain read access to any known JavaBean file residing on a host running Resin On Resin webservers, JavaBean files reside in a protected directory, '/WEB-INF/classes/' Unfortunately, this protection can be bypassed due to an i ...