Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-1953

Overview

Vulnerability Score 7.8 7.8
CVE Id CVE-2006-1953
Last Modified 07 Mar 2011 09:34:36
Published 17 May 2006 06:06:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2006-1953

Summary

Directory traversal vulnerability in Caucho Resin 3.0.17 and 3.0.18 for Windows allows remote attackers to read arbitrary files via a "C:%5C" (encoded drive letter) in a URL.

Vulnerable Systems

Application

  • Caucho Technology Resin 3.0.17

  • Caucho Technology Resin 3.0.18


References

BID - 18005

BUGTRAQ - 20060516 Caucho Resin Windows Directory Traversal Vulnerability

VUPEN - ADV-2006-1831

XF - resin-webserver-directory-traversal(26478)

MISC - http://www.rapid7.com/advisories/R7-0024.html

OSVDB - 25570

SECTRACK - 1016109

SREASON - 904

SECUNIA - 20125


Last Updated: 27 May 2016 10:42:16