Information Disclosure Vulnerability in Resin Web and Application Server
An information-disclosure vulnerability exists in Resin 2.1.1 and 2.1.2 for Windows.
July 18, 2002
Reported July 17, 2002, by PeterGründl.
VERSIONS AFFECTED
Resin Web and Application Server 2.1.1 and 2.1.2 for Windows 2000
DESCRIPTION
Aninformation-disclosure vulnerability exists in Resin 2.1.1 and 2.1.2 for Windows2000 that can result in displaying the physical path to the Web root. Byrequesting certain disk operating system (DOS) devices, such as lpt9.xtp, anattacker can cause the server to display an error message with the path to Webroot in the returned-error information.
VENDOR RESPONSE
Thevendor, Caucho Technology, recommends thataffected users download the latestbuild, which doesn't contain this vulnerability.
CREDIT
Discovered by PeterGründl.
About the Author
You May Also Like