First published: Wed May 17 2006(Updated: )
Directory traversal vulnerability in the viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to read arbitrary files under other web roots via the contextpath parameter. NOTE: this issue can produce resultant path disclosure when the parameter is invalid.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Caucho Resin | =3.0.17 | |
Caucho Resin | =3.0.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2438 is classified as a medium severity vulnerability.
To fix CVE-2006-2438, you should upgrade Caucho Resin to version 3.0.19 or later, where the vulnerability is resolved.
CVE-2006-2438 affects Caucho Resin versions 3.0.17 and 3.0.18.
Yes, CVE-2006-2438 allows remote attackers to exploit the vulnerability to read arbitrary files.
The CVE-2006-2438 vulnerability arises from a directory traversal issue in the viewfile servlet of the resin-doc package.