A vulnerability has been reported in Resin Server, deployed on a Microsoft Windows platform, that may allow remote attackers to view sensitive path information. Caucho Technology's Resin ships with a number of servlets which may reveal the absolute path of the servlet installation when requested via HTTP. This information will give the attacker filesystem structure information of the host running Resin. This issue has been reported in Resin 2.0.5 - 2.1.2.
A vulnerability has been reported in Resin Server, deployed on a Microsoft Windows platform, that may allow remote attackers to view sensitive path information. Caucho Technology's Resin ships with a number of servlets which may reveal the absolute path of the servlet installation when requested via HTTP. This information will give the attacker filesystem structure information of the host running Resin. This issue has been reported in Resin 2.0.5 - 2.1.2.