CVE-2012-2969 Information

Share on:

Description

Caucho Quercus as distributed in Resin before 4.0.29 allows remote attackers to bypass intended restrictions on filename extensions for created files via a 00 sequence in a pathname within an HTTP request.

Reference

http://caucho.com/resin-4.0/changes/changes.xtp http://en.securitylab.ru/lab/ http://en.securitylab.ru/lab/PT-2012-05 http://www.kb.cert.org/vuls/id/309979