PT-2014-4988 · Caucho · Resin Pro
Angelo Prado
+1
·
Published
2014-07-26
·
Updated
2014-07-28
·
CVE-2014-2966
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Resin Pro versions prior to 4.0.40
Description
The issue concerns the ISO-8859-1 encoder, which does not properly perform Unicode transformations. This allows remote attackers to bypass intended text restrictions by using crafted characters. For example, it can be used to bypass an XSS protection mechanism.
Recommendations
For versions prior to 4.0.40, update to version 4.0.40 or later to resolve the issue. As a temporary workaround, consider restricting the input of crafted characters to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Resin Pro