First published: Thu Mar 18 2004(Updated: )
Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP request for "WEB-INF..", which is equivalent to "WEB-INF" in Windows.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Caucho Technology Resin | =2.1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0281 is classified as a moderate vulnerability impacting sensitive information disclosure.
To fix CVE-2004-0281, ensure that you upgrade to a version of Caucho Technology Resin that is higher than 2.1.12.
CVE-2004-0281 allows remote attackers to access and view the contents of the /WEB-INF/ directory via crafted HTTP requests.
CVE-2004-0281 affects Caucho Technology Resin version 2.1.12.
Yes, CVE-2004-0281 can lead to further exploitation by allowing attackers to access sensitive application files.