Vulnerabilities > CVE-2007-2440 - Information Disclosure vulnerability in Caucho Resin

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
caucho-technology
nessus
exploit available

Summary

Directory traversal vulnerability in Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to read certain files via a .. (dot dot) in a URI containing a "\web-inf" sequence.

Vulnerable Configurations

Part Description Count
Application
Caucho_Technology
2

Exploit-Db

descriptionCaucho Resin 3.1 \web-inf Traversal Arbitrary File Access. CVE-2007-2440. Remote exploit for windows platform
idEDB-ID:30038
last seen2016-02-03
modified2007-05-15
published2007-05-15
reporterDerek Abdine
sourcehttps://www.exploit-db.com/download/30038/
titleCaucho Resin 3.1 \web-inf Traversal Arbitrary File Access

Nessus

NASL familyWeb Servers
NASL idRESIN_DIR_TRAVERSAL2.NASL
descriptionThe remote host is running Resin, an application server. The installation of Resin on the remote host allows an unauthenticated, remote attacker to gain access to the web-inf directories, or any known subdirectories, on the affected Windows host, which could lead to a loss of confidentiality.
last seen2020-06-01
modified2020-06-02
plugin id25241
published2007-05-16
reporterThis script is Copyright (C) 2007-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/25241
titleResin for Windows \WEB-INF Traversal Arbitrary File Access