CVE-2000-1224: Medium severity Caucho Technology Resin vulnerability
Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) "..", (2) "%2e..", (3) "%81", (4) "%82", and others.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2000-1224?
CVE-2000-1224 is considered a moderate severity vulnerability due to the potential for unauthorized access to sensitive JSP source code.
How do I fix CVE-2000-1224?
To fix CVE-2000-1224, upgrade to a patched version of Caucho Technology Resin that mitigates this vulnerability.
What versions of Caucho Technology Resin are affected by CVE-2000-1224?
CVE-2000-1224 affects Caucho Technology Resin version 1.2 and possibly earlier versions, including 1.1.5.
What type of attack does CVE-2000-1224 facilitate?
CVE-2000-1224 facilitates a source code disclosure attack, allowing remote attackers to view JSP source files.
Is CVE-2000-1224 applicable to all systems running Caucho Resin?
CVE-2000-1224 is specifically applicable to systems running affected versions of Caucho Resin, prior to any security updates.