Resin Application Server Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2012-2968 - Vulnerability Database

Resin Application Server Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2012-2968

Medium
Reference: CVE-2012-2968
Title: Resin Application Server Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Overview:

Directory traversal vulnerability in Caucho Quercus as distributed in Resin before 4.0.29 allows remote attackers to create files in arbitrary directories via a .. (dot dot) in a pathname within an HTTP request.