Skip to main content

Vendor/product archive

caucho / resin CVEs

Beta · best-effort

11 CVEs tagged to caucho / resin0 Critical, 4 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2021-44138

Published Apr 4, 2022

There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ;…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2966

Published Jul 26, 2014

The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2969

Published Aug 12, 2012

Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filename extensions for created files via a %00 sequence in a pat…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2968

Published Aug 12, 2012

Directory traversal vulnerability in Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to create files in arbitrary directories via a .. (dot dot) in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2967

Published Aug 12, 2012

Caucho Quercus, as distributed in Resin before 4.0.29, does not properly implement the == (equals sign equals sign) operator for comparisons, which has unspecified impact and cont…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-2966

Published Aug 12, 2012

Caucho Quercus, as distributed in Resin before 4.0.29, overwrites entries in the SERVER superglobal array on the basis of POST parameters, which has unspecified impact and remote…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-2965

Published Aug 12, 2012

Caucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of variables, which has unknown impact and remote attack vector…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-2032

Published May 24, 2010

Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remot…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2462

Published Jun 30, 2008

Cross-site scripting (XSS) vulnerability in the viewfile documentation command in Caucho Resin before 3.0.25, and 3.1.x before 3.1.4, allows remote attackers to inject arbitrary w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0281

Published Nov 23, 2004

Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP request for "WEB-INF..", which is…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1