Vulnerabilities
Vulnerable Software
Multiple cross-site scripting (XSS) vulnerabilities in example scripts in Caucho Technology Resin 2.0 through 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) env.jsp, (2) form.jsp, (3) session.jsp, (4) the move parameter to tictactoe.jsp, or the (5) name or (6) comment fields to guestbook.jsp.
CVSS Score
4.3
EPSS Score
0.003
Published
2003-12-31
Resin 2.1.1 allows remote attackers to cause a denial of service (memory consumption and hang) via a URL with long variables for non-existent resources.
CVSS Score
5.0
EPSS Score
0.007
Published
2002-12-31
Resin 2.1.1 allows remote attackers to cause a denial of service (thread and connection consumption) via multiple URL requests containing the DOS 'CON' device name and a registered file extension such as .jsp or .xtp.
CVSS Score
5.0
EPSS Score
0.007
Published
2002-12-31
Resin 2.0.5 through 2.1.2 allows remote attackers to reveal physical path information via a URL request for the example Java class file HelloServlet.
CVSS Score
5.0
EPSS Score
0.003
Published
2002-12-31
Caucho Technology Resin server 2.1.1 to 2.1.2 allows remote attackers to obtain server's root path via requests for MS-DOS device names such as lpt9.xtp.
CVSS Score
5.0
EPSS Score
0.003
Published
2002-12-31


Contact Us

Shodan ® - All rights reserved