vendor:
Resin Professional Web And Application Server
by:
Gjoko 'LiquidWorm' Krstic
7,5
CVSS
HIGH
Source Code Disclosure
200
CWE
Product Name: Resin Professional Web And Application Server
Affected Version From: Resin Professional Web And Application Server 4.0.36
Affected Version To: Resin Professional Web And Application Server 4.0.36
Patch Exists: NO
Related CWE: N/A
CPE: a:caucho_technology:resin_professional_web_and_application_server:4.0.36
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 amd64 6.1
2013
Resin Application Server 4.0.36 Source Code Disclosure Vulnerability
The vulnerability is caused do to an improper sanitization of the 'file' parameter when used for reading help files. An attacker can exploit this vulnerability by directly requesting a '.jsp' file for example in the root directory of the server to view its source code that might reveal sensitive information.
Mitigation:
Ensure that the 'file' parameter is properly sanitized before being used for reading help files.