CVE-2007-2440

Caucho Resin <3.1.0 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-2440. PoCs published by Derek Abdine.

AI-analyzed exploit summary The provided text describes an information disclosure vulnerability in Caucho Resin 3.1.0 on Windows, where improper sanitization allows access to sensitive files via path traversal. The example URL demonstrates accessing the WEB-INF directory, which may contain configuration files or other sensitive data.

Description

Directory traversal vulnerability in Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to read certain files via a .. (dot dot) in a URI containing a "\web-inf" sequence.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Derek Abdine · textremotewindows
https://www.exploit-db.com/exploits/30038

The provided text describes an information disclosure vulnerability in Caucho Resin 3.1.0 on Windows, where improper sanitization allows access to sensitive files via path traversal. The example URL demonstrates accessing the WEB-INF directory, which may contain configuration files or other sensitive data.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Caucho Resin 3.1.0 (Windows)
No auth needed
Prerequisites: Target running Caucho Resin 3.1.0 on Windows · Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018061
Patch, Vendor Advisory x_refsource_misc
http://www.rapid7.com/advisories/R7-0029.jsp
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34296
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25286
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1824
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/36058
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23985
Various Sources x_refsource_confirm
http://www.caucho.com/resin-3.1/changes/changes.xtp

Scores

EPSS 0.0364
EPSS Percentile 88.1%

Details

Status published
Products (1)
caucho_technology/resin < 3.1.0 (2 CPE variants)
Published May 16, 2007
Tracked Since Feb 18, 2026