Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-2437

EPSS 5.13% · P90
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-2437

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to obtain the source code for file under the web root via the file parameter.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Caucho Resin 某CGI程序 输入验证漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Resin是一款由Caucho Technology开发的WEB服务器,可使用在Microsoft Windos操作系统下。 Resin的某个CGI程序实现上存在输入验证漏洞,远程攻击者可能利用此漏洞读取Web主目录下的任意文件,包括JSP源码或类文件。 默认下Resin的/webapps目录下/resin-doc中包含有一个扩展war文件。该文档包含有用于在集成的手册中浏览文件的servlet: http://targetsystem/resin-doc/viewfile/?contextpath=%2
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-2437

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-2437

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-05-17 · 21 CVEs total

CVE-2006-2428DUware Dubanner add.asp可 任意文件上传漏洞
CVE-2006-2438Caucho Resin viewfile程序组件 目录遍历漏洞
CVE-2006-2436WebSphere Application Server FFDC日志 信息泄露漏洞
CVE-2006-2435ibm websphere_application_server 未明漏洞
CVE-2006-2434WebSphere 普通配置模块 + CommonArchive J2EE 模块未明漏洞
CVE-2006-2433ibm websphere_application_server 未明漏洞
CVE-2006-2432IBM WebSphere Application Server LTPA令牌 权限许可和访问控制漏洞
CVE-2006-2431IBM WebSphere 500 Internal Server Error 跨站脚本攻击漏洞
CVE-2006-2430IBM WebSphere Application Server addNode.log 信息泄露漏洞
CVE-2006-2429ibm websphere_application_server 未明漏洞
CVE-2005-4802Flexbackup 临时文件漏洞
CVE-2006-2427多个版本 freshclam config-file命令 信息泄露漏洞
CVE-2006-2426Sun Java Runtime Environment Font.createFont函数 拒绝服务漏洞
CVE-2006-2425PHPRemoteView PRV.PHP 多个跨站脚本攻击漏洞
CVE-2006-2424EZUserManager EZusermanager_pwd_forgott.PHP 远程文件包含漏洞
CVE-2006-2423Confixx Index.PHP 跨站脚本攻击漏洞
CVE-2006-2422phpCOIN Email 信息泄露漏洞
CVE-2006-2421Pragma FortressSSH SSH_MSG_KEXINIT 远程缓冲区溢出漏洞
CVE-2006-1953Caucho Resin 用户请求 目录遍历漏洞
CVE-2005-4803Graphviz不安全临时文件创建漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2006-2437

No comments yet


Leave a comment