Resin Application Server Permissions Privileges and Access Controls Vulnerability - CVE-2014-2966 - Vulnerability Database

Resin Application Server Permissions Privileges and Access Controls Vulnerability - CVE-2014-2966

Medium
Reference: CVE-2014-2966
Title: Resin Application Server Permissions Privileges and Access Controls Vulnerability
Overview:

The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations which allows remote attackers to bypass intended text restrictions via crafted characters as demonstrated by bypassing an XSS protection mechanism.