First published: Thu Nov 23 2000(Updated: )
Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) "..", (2) "%2e..", (3) "%81", (4) "%82", and others.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Caucho Resin | =1.2 | |
Caucho Resin | =1.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1224 is considered a moderate severity vulnerability due to the potential for unauthorized access to sensitive JSP source code.
To fix CVE-2000-1224, upgrade to a patched version of Caucho Technology Resin that mitigates this vulnerability.
CVE-2000-1224 affects Caucho Technology Resin version 1.2 and possibly earlier versions, including 1.1.5.
CVE-2000-1224 facilitates a source code disclosure attack, allowing remote attackers to view JSP source files.
CVE-2000-1224 is specifically applicable to systems running affected versions of Caucho Resin, prior to any security updates.