5
CVSSv2

CVE-2014-2966

Published: 26/07/2014 Updated: 28/07/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The ISO-8859-1 encoder in Resin Pro prior to 4.0.40 does not properly perform Unicode transformations, which allows remote malicious users to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism.

Vulnerable Product Search on Vulmon Subscribe to Product

caucho resin

caucho resin 4.0.38

caucho resin 4.0.37

caucho resin 4.0.36