Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2002-1987

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Resin是一款由Caucho Technology公司分发的WEB服务器程序,使用于Microsoft Windows操作系统下。 Resin WEB服务程序包含的样例脚本view_source.jsp对用户输入缺少过滤,远程攻击者可以利用此漏洞进行目录遍历攻击。 Resin WEB服务程序中存在样例脚本view_source.jsp,view_source.jsp脚本在解析包含'/../'字符的特殊请求进行了过滤,不过攻击者可以通过提交包含'\..\'字符的请求进行目录遍历攻击,这样可绕过chroot

AI Predicted 7.5 Difficulty: Trivial EPSS 2.55% · P84
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2002-1987

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Directory traversal vulnerability in view_source.jsp in Resin 2.1.2 allows remote attackers to read arbitrary files via a "\.." (backslash dot dot).
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Caucho Technology Resin服务程序view_source.jsp远程文件泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Resin是一款由Caucho Technology公司分发的WEB服务器程序,使用于Microsoft Windows操作系统下。 Resin WEB服务程序包含的样例脚本view_source.jsp对用户输入缺少过滤,远程攻击者可以利用此漏洞进行目录遍历攻击。 Resin WEB服务程序中存在样例脚本view_source.jsp,view_source.jsp脚本在解析包含'/../'字符的特殊请求进行了过滤,不过攻击者可以通过提交包含'\..\'字符的请求进行目录遍历攻击,这样可绕过chroot
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2002-1987

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2002-1987

登录查看更多情报信息。

Vendor Advisories for CVE-2002-1987 (2)

Other References for CVE-2002-1987 (1)

Same Patch Batch · n/a · 2005-07-14 · 176 CVEs total

CVE-2002-2032 PHP-Nuke SQL_Debug调试信息泄露漏洞
CVE-2002-2022 Kaffe OpenVM NoClassDefFoundError格式字符串漏洞
CVE-2002-2023 Shingo beep2任意文件读取漏洞
CVE-2002-2024 Horde IMP 2.2.7存在路径泄露漏洞
CVE-2002-2025 Lotus Domino MS-DOS设备文件名拒绝服务攻击漏洞
CVE-2002-2026 BrowseFTP Client缓冲区溢出漏洞
CVE-2002-2027 Database of our owlish Wisdom 安全漏洞
CVE-2002-2028 微软Windows NT不准确的登录日志漏洞
CVE-2002-2029 Apache Win32 PHP.EXE远程文件泄露漏洞
CVE-2002-2030 SQLData Enterprise Server缓冲区溢出漏洞
CVE-2002-2031 Microsoft Internet Explorer 安全漏洞
CVE-2002-2037 Solaris漏洞威胁Cisco Media Gateway Controller的安全
CVE-2002-2042 QNX 'ptrace()'任意进程修改漏洞
CVE-2002-2041 QNX RTOS PKG-Installer缓冲区溢出漏洞
CVE-2002-2040 QNX RTOS phgrafx特权提升漏洞
CVE-2002-2039 QNX RTOS su密码哈希泄露漏洞
CVE-2002-2038 新一代的POSIX线程共享内存服务拒绝漏洞
CVE-2002-2035 RealityScape MyLoginSQL注入漏洞
CVE-2002-2033 Faqmanager.cgi NULL字符泄露任意文件漏洞
CVE-2002-2034 John Hardin Procmail Email Sanitizer分段Mime识别漏洞

Showing top 20 of 176 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2002-1987

No comments yet


Leave a comment