// For flags

CVE-2007-2441

Caucho Resin 3.1 - Encoded Space Request Full Path Disclosure

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to obtain the system path via certain URLs associated with (1) deploying web applications or (2) displaying .xtp files.

Caucho Resin Professional 3.1.0 y Caucho Resin 3.1.0 y versiones anteriores para Windows permiten a atacantes remotos obtener la ruta del sistema mediante URLs concretas asociadas con (1) desplegando aplicaciones web รณ (2) visualizando .xtp files.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-05-01 CVE Reserved
  • 2007-05-15 First Exploit
  • 2007-05-16 CVE Published
  • 2024-07-11 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Caucho Technology
Search vendor "Caucho Technology"
Resin
Search vendor "Caucho Technology" for product "Resin"
<= 3.1.0
Search vendor "Caucho Technology" for product "Resin" and version " <= 3.1.0"
professional_windows
Affected
Caucho Technology
Search vendor "Caucho Technology"
Resin
Search vendor "Caucho Technology" for product "Resin"
<= 3.1.0
Search vendor "Caucho Technology" for product "Resin" and version " <= 3.1.0"
windows
Affected