Information Disclosure Vulnerability in Resin Web and Application Server

An information-disclosure vulnerability exists in Resin 2.1.1 and 2.1.2 for Windows.

Ken Pfeil

July 18, 2002

1 Min Read
ITPro Today logo

Reported July 17, 2002, by PeterGründl.

VERSIONS AFFECTED

  • Resin Web and Application Server 2.1.1 and 2.1.2 for Windows 2000

 

DESCRIPTION

Aninformation-disclosure vulnerability exists in Resin 2.1.1 and 2.1.2 for Windows2000 that can result in displaying the physical path to the Web root. Byrequesting certain disk operating system (DOS) devices, such as lpt9.xtp, anattacker can cause the server to display an error message with the path to Webroot in the returned-error information.

 


VENDOR RESPONSE

 

Thevendor, Caucho Technology, recommends thataffected users download the latestbuild, which doesn't contain this vulnerability.

 

CREDIT
Discovered by PeterGründl.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like