Resin Application Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2969)
Description
Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filename extensions for created files via a %00 sequence in a pathname within an HTTP request.