CVE-2004-0280: Medium severity Caucho Technology Resin vulnerability
Published Mar 18, 2004
·Updated
Caucho Technology Resin 2.1.12 allows remote attackers to view JSP source via an HTTP request to a .jsp file that ends in a "%20" (encoded space character), e.g. index.jsp%20.
Affected Software
1 affected component
Caucho Technology Resin=2.1.12
Event History
Mar 18, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0280?
CVE-2004-0280 is considered a high severity vulnerability due to its potential for data exposure.
2
How does CVE-2004-0280 impact users?
CVE-2004-0280 allows remote attackers to view JSP source code, which can lead to sensitive information disclosure.
3
What versions of Resin are affected by CVE-2004-0280?
CVE-2004-0280 specifically affects Caucho Technology Resin version 2.1.12.
4
How can I fix CVE-2004-0280?
The best way to fix CVE-2004-0280 is to upgrade to a version of Caucho Technology Resin that is not vulnerable to this issue.
5
What happens if CVE-2004-0280 is exploited?
If CVE-2004-0280 is exploited, an attacker may gain access to the source code of JSP files, potentially revealing application logic and sensitive data.