VulnerabilityModified
CVE-2012-2968
Directory traversal vulnerability in Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to create files in arbitrary directories via a ..
MEDIUM 5.0EPSS 3.49%
Does this matter?
Lower severity and a low EPSS score (3.49%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to create files in arbitrary directories via a .. (dot dot) in a pathname within an HTTP request.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 3.49% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- caucho/resin
- Source
- cret@cert.org
References
- http://caucho.com/resin-4.0/changes/changes.xtp
- http://en.securitylab.ru/lab/
- http://en.securitylab.ru/lab/PT-2012-05
- http://www.kb.cert.org/vuls/id/309979US Government Resource
- http://caucho.com/resin-4.0/changes/changes.xtp
- http://en.securitylab.ru/lab/
- http://en.securitylab.ru/lab/PT-2012-05
- http://www.kb.cert.org/vuls/id/309979US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.