Resin Application Server Permissions Privileges and Access Controls Vulnerability - CVE-2012-2969
Caucho Quercus as distributed in Resin before 4.0.29 allows remote attackers to bypass intended restrictions on filename extensions for created files via a 00 sequence in a pathname within an HTTP request.