Lucene search

K
cve[email protected]CVE-2000-1224
HistoryMay 19, 2005 - 4:00 a.m.

CVE-2000-1224

2005-05-1904:00:00
web.nvd.nist.gov
26
resin 1.2
jsp source exposure
http request
cve-2000-1224
remote attacks

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.2 High

AI Score

Confidence

Low

0.028 Low

EPSS

Percentile

90.7%

Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) “…”, (2) “%2e…”, (3) “%81”, (4) “%82”, and others.

Affected configurations

NVD
Node
caucho_technologyresinMatch1.1.5
OR
caucho_technologyresinMatch1.2

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.2 High

AI Score

Confidence

Low

0.028 Low

EPSS

Percentile

90.7%

Related for CVE-2000-1224