CVE-2006-2438: Medium severity Caucho Technology Resin vulnerability
Directory traversal vulnerability in the viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to read arbitrary files under other web roots via the contextpath parameter. NOTE: this issue can produce resultant path disclosure when the parameter is invalid.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2438?
CVE-2006-2438 is classified as a medium severity vulnerability.
How do I fix CVE-2006-2438?
To fix CVE-2006-2438, you should upgrade Caucho Resin to version 3.0.19 or later, where the vulnerability is resolved.
What does CVE-2006-2438 affect?
CVE-2006-2438 affects Caucho Resin versions 3.0.17 and 3.0.18.
Can CVE-2006-2438 lead to unauthorized file access?
Yes, CVE-2006-2438 allows remote attackers to exploit the vulnerability to read arbitrary files.
What is the context of the CVE-2006-2438 vulnerability?
The CVE-2006-2438 vulnerability arises from a directory traversal issue in the viewfile servlet of the resin-doc package.