Korean
<< Back
VID 22235
Severity 20
Port 80, ...
Protocol TCP
Class Servlet
Detailed Description Resin example file reveals the full path to the installation directory. Resin, developed by Caucho Technology, is a servlet and Java Server Pages (JSP) engine that supports Java and JavaScript. One of the example Java class files in Resin versions 2.0.5 through 2.1.2, HelloServlet, could allow a remote attacker to obtain the full path to the Resin directory. The attacker may use this information in order to gain unauthorized access to the webserver.

* References:
http://archives.neohapsis.com/archives/bugtraq/2002-06/0292.html

* Platforms Affected:
Resin 2.0.5 to 2.1.2
Unix Any version
Windows Any version
Recommendation Upgrade to the latest version of Resin (2.1.11 or later), available from the Caucho Technology Web site at http://caucho.com/products/resin/download

-- OR --

As a workaround, remove the "Examples" directory, if the sample scripts are not needed.
Related URL CVE-2002-1990 (CVE)
Related URL 5095 (SecurityFocus)
Related URL 9419 (ISS)