Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) .., (2) %2e.., (3) %81, (4) %82, and others.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Resin | Caucho_technology | 1.1.5 (including) | 1.1.5 (including) |
Resin | Caucho_technology | 1.2 (including) | 1.2 (including) |