CVE-2007-2441 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 3.3% (pctl 88)
Patch early
A public exploit exists.
Description
Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to obtain the system path via certain URLs associated with (1) deploying web applications or (2) displaying .xtp files.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 3.27% — more likely to be exploited than 88% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-05-16 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| caucho technology | resin |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Caucho Resin 3.1 - Encoded Space Request Full Path Disclosure | 2007-05-15 |
References
- http://osvdb.org/36057
- http://secunia.com/advisories/25286
- http://www.caucho.com/resin-3.1/changes/changes.xtp
- http://www.rapid7.com/advisories/R7-0030.jsp
- http://www.securityfocus.com/bid/23985
- http://www.securitytracker.com/id?1018061
- http://www.vupen.com/english/advisories/2007/1824
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34293
- http://osvdb.org/36057
- http://secunia.com/advisories/25286
- http://www.caucho.com/resin-3.1/changes/changes.xtp
- http://www.rapid7.com/advisories/R7-0030.jsp
- http://www.securityfocus.com/bid/23985
- http://www.securitytracker.com/id?1018061
- http://www.vupen.com/english/advisories/2007/1824
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34293
→ the Explorer · watch your stack · NVD