Exploitation Summary
EIP tracks 1 public exploit for CVE-2000-1224. PoCs published by benjurry.
AI-analyzed exploit summary This is a writeup describing a path traversal vulnerability in Resin and ServletExec that allows disclosure of JSP source code by appending specific characters to the URL. The vulnerability is platform-dependent and affects Apache (Win32), Resin Web Server, and IIS 5.
Description
Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) "..", (2) "%2e..", (3) "%81", (4) "%82", and others.
Exploits (1)
This is a writeup describing a path traversal vulnerability in Resin and ServletExec that allows disclosure of JSP source code by appending specific characters to the URL. The vulnerability is platform-dependent and affects Apache (Win32), Resin Web Server, and IIS 5.