Lucene search

K
cveCertccCVE-2012-2969
HistoryAug 12, 2012 - 4:55 p.m.

CVE-2012-2969

2012-08-1216:55:01
CWE-264
certcc
web.nvd.nist.gov
25
caucho quercus
resin
cve-2012-2969
remote attack

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

6.9

Confidence

Low

EPSS

0.008

Percentile

82.3%

Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filename extensions for created files via a %00 sequence in a pathname within an HTTP request.

Affected configurations

Nvd
Node
cauchoresinRange4.0.28
OR
cauchoresinMatch2.0.0
OR
cauchoresinMatch2.0.1
OR
cauchoresinMatch2.0.2
OR
cauchoresinMatch2.0.3
OR
cauchoresinMatch2.0.4
OR
cauchoresinMatch2.0.5
OR
cauchoresinMatch2.1.0
OR
cauchoresinMatch2.1.1
OR
cauchoresinMatch2.1.2
OR
cauchoresinMatch2.1.3
OR
cauchoresinMatch2.1.4
OR
cauchoresinMatch2.1.5
OR
cauchoresinMatch2.1.6
OR
cauchoresinMatch2.1.7
OR
cauchoresinMatch2.1.8
OR
cauchoresinMatch2.1.9
OR
cauchoresinMatch2.1.10
OR
cauchoresinMatch2.1.11
OR
cauchoresinMatch2.1.12
OR
cauchoresinMatch2.1.13
OR
cauchoresinMatch2.1.14
OR
cauchoresinMatch2.1.15
OR
cauchoresinMatch2.1.16
OR
cauchoresinMatch2.1.snap
OR
cauchoresinMatch3.0.0
OR
cauchoresinMatch3.0.1beta
OR
cauchoresinMatch3.0.2beta
OR
cauchoresinMatch3.0.3
OR
cauchoresinMatch3.0.4
OR
cauchoresinMatch3.0.5
OR
cauchoresinMatch3.0.6
OR
cauchoresinMatch3.0.7
OR
cauchoresinMatch3.0.8
OR
cauchoresinMatch3.0.9
OR
cauchoresinMatch3.0.10
OR
cauchoresinMatch3.0.11
OR
cauchoresinMatch3.0.12
OR
cauchoresinMatch3.0.13
OR
cauchoresinMatch3.0.14
OR
cauchoresinMatch3.0.15
OR
cauchoresinMatch3.0.16
OR
cauchoresinMatch3.0.17
OR
cauchoresinMatch3.0.18
OR
cauchoresinMatch3.0.19
OR
cauchoresinMatch3.0.20
OR
cauchoresinMatch3.1.0
OR
cauchoresinMatch3.1.1
OR
cauchoresinMatch3.1.2
OR
cauchoresinMatch3.1.3
OR
cauchoresinMatch3.1.4
OR
cauchoresinMatch3.1.5
OR
cauchoresinMatch3.1.6
OR
cauchoresinMatch3.1.7
OR
cauchoresinMatch3.1.8
OR
cauchoresinMatch3.1.9
OR
cauchoresinMatch3.1.10
OR
cauchoresinMatch3.1.11
OR
cauchoresinMatch3.1.12
OR
cauchoresinMatch3.1.13
OR
cauchoresinMatch4.0.0
OR
cauchoresinMatch4.0.1
OR
cauchoresinMatch4.0.2
OR
cauchoresinMatch4.0.3
OR
cauchoresinMatch4.0.4
OR
cauchoresinMatch4.0.5
OR
cauchoresinMatch4.0.6
OR
cauchoresinMatch4.0.7
OR
cauchoresinMatch4.0.8
OR
cauchoresinMatch4.0.9
OR
cauchoresinMatch4.0.10
OR
cauchoresinMatch4.0.11
OR
cauchoresinMatch4.0.12
OR
cauchoresinMatch4.0.13
OR
cauchoresinMatch4.0.14
OR
cauchoresinMatch4.0.15
OR
cauchoresinMatch4.0.16
OR
cauchoresinMatch4.0.17
OR
cauchoresinMatch4.0.18
OR
cauchoresinMatch4.0.19
OR
cauchoresinMatch4.0.20
OR
cauchoresinMatch4.0.21
OR
cauchoresinMatch4.0.22
OR
cauchoresinMatch4.0.23
OR
cauchoresinMatch4.0.24
OR
cauchoresinMatch4.0.25
OR
cauchoresinMatch4.0.26
OR
cauchoresinMatch4.0.27
VendorProductVersionCPE
cauchoresin*cpe:2.3:a:caucho:resin:*:*:*:*:*:*:*:*
cauchoresin2.0.0cpe:2.3:a:caucho:resin:2.0.0:*:*:*:*:*:*:*
cauchoresin2.0.1cpe:2.3:a:caucho:resin:2.0.1:*:*:*:*:*:*:*
cauchoresin2.0.2cpe:2.3:a:caucho:resin:2.0.2:*:*:*:*:*:*:*
cauchoresin2.0.3cpe:2.3:a:caucho:resin:2.0.3:*:*:*:*:*:*:*
cauchoresin2.0.4cpe:2.3:a:caucho:resin:2.0.4:*:*:*:*:*:*:*
cauchoresin2.0.5cpe:2.3:a:caucho:resin:2.0.5:*:*:*:*:*:*:*
cauchoresin2.1.0cpe:2.3:a:caucho:resin:2.1.0:*:*:*:*:*:*:*
cauchoresin2.1.1cpe:2.3:a:caucho:resin:2.1.1:*:*:*:*:*:*:*
cauchoresin2.1.2cpe:2.3:a:caucho:resin:2.1.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 881

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

6.9

Confidence

Low

EPSS

0.008

Percentile

82.3%

Related for CVE-2012-2969