CVE-2012-2968 Information

Share on:

Description

Directory traversal vulnerability in Caucho Quercus as distributed in Resin before 4.0.29 allows remote attackers to create files in arbitrary directories via a .. (dot dot) in a pathname within an HTTP request.

Reference

http://caucho.com/resin-4.0/changes/changes.xtp http://en.securitylab.ru/lab/ http://en.securitylab.ru/lab/PT-2012-05 http://www.kb.cert.org/vuls/id/309979