CVE-2006-2437: Medium severity Caucho Technology Resin vulnerability
Published May 17, 2006
·Updated
The viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to obtain the source code for file under the web root via the file parameter.
Affected Software
2 affected components
Caucho Technology Resin=3.0.18
Caucho Technology Resin=3.0.17
Remediation
Patch Available
Event History
May 17, 2006
CVE Published
10:06 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2437?
CVE-2006-2437 has a high severity level due to its potential for exposing sensitive source code.
2
How do I fix CVE-2006-2437?
To fix CVE-2006-2437, upgrade to a version of Caucho Resin that is not affected, such as versions later than 3.0.18.
3
What is the impact of CVE-2006-2437?
The impact of CVE-2006-2437 allows remote attackers to access the source code of files under the web root, leading to possible exploitation.
4
Which versions are affected by CVE-2006-2437?
CVE-2006-2437 affects Caucho Resin versions 3.0.17 and 3.0.18.
5
Can CVE-2006-2437 be exploited remotely?
Yes, CVE-2006-2437 can be exploited remotely by attackers with knowledge of the file parameter.