| VID |
22235 |
| Severity |
20 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
Servlet |
| Detailed Description |
Resin example file reveals the full path to the installation directory. Resin, developed by Caucho Technology, is a servlet and Java Server Pages (JSP) engine that supports Java and JavaScript. One of the example Java class files in Resin versions 2.0.5 through 2.1.2, HelloServlet, could allow a remote attacker to obtain the full path to the Resin directory. The attacker may use this information in order to gain unauthorized access to the webserver.
* References: http://archives.neohapsis.com/archives/bugtraq/2002-06/0292.html
* Platforms Affected: Resin 2.0.5 to 2.1.2 Unix Any version Windows Any version |
| Recommendation |
Upgrade to the latest version of Resin (2.1.11 or later), available from the Caucho Technology Web site at http://caucho.com/products/resin/download
-- OR --
As a workaround, remove the "Examples" directory, if the sample scripts are not needed. |
| Related URL |
CVE-2002-1990 (CVE) |
| Related URL |
5095 (SecurityFocus) |
| Related URL |
9419 (ISS) |
|