PT-2014-4988 · Caucho · Resin Pro
Angelo Prado
+1
·
Publicado
2014-07-26
·
Atualizado
2014-07-28
·
CVE-2014-2966
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Resin Pro versions prior to 4.0.40
Description
The issue concerns the ISO-8859-1 encoder, which does not properly perform Unicode transformations. This allows remote attackers to bypass intended text restrictions by using crafted characters. For example, it can be used to bypass an XSS protection mechanism.
Recommendations
For versions prior to 4.0.40, update to version 4.0.40 or later to resolve the issue. As a temporary workaround, consider restricting the input of crafted characters to minimize the risk of exploitation.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Resin Pro