36057vdb entry
http://osvdb.org/36057 CVE-2007-2441
Caucho Resin 3.1 - Encoded Space Request Full Path Disclosure
Record summary
CVE-2007-2441 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to obtain the system path via certain URLs associated with (1) deploying web applications or (2) displaying .xtp files.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCaucho Resin 3.1 - Encoded Space Request Full Path DisclosureExploitDB exploitby Derek AbdineNot analyzed1 file
References
925286Third-party advisory
http://secunia.com/advisories/25286 caucho.comConfirmation
http://www.caucho.com/resin-3.1/changes/changes.xtp rapid7.com
http://www.rapid7.com/advisories/R7-0030.jsp 23985vdb entry
http://www.securityfocus.com/bid/23985 1018061vdb entry
http://www.securitytracker.com/id?1018061 ADV-2007-1824vdb entry
http://www.vupen.com/english/advisories/2007/1824 resin-multiple-path-disclosure(34293)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/34293 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-2441