Unrated severityNVD Advisory· Published May 17, 2006· Updated Apr 16, 2026
CVE-2006-2438
CVE-2006-2438
Description
Directory traversal vulnerability in the viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to read arbitrary files under other web roots via the contextpath parameter. NOTE: this issue can produce resultant path disclosure when the parameter is invalid.
Affected products
2cpe:2.3:a:caucho_technology:resin:3.0.17:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:caucho_technology:resin:3.0.17:*:*:*:*:*:*:*
- cpe:2.3:a:caucho_technology:resin:3.0.18:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.securityfocus.com/archive/1/434145nvdExploitPatchVendor Advisory
- www.securityfocus.com/bid/18007nvdExploitPatch
- archives.neohapsis.com/archives/fulldisclosure/2006-05/0384.htmlnvd
- secunia.com/advisories/20125nvd
- securityreason.com/securityalert/908nvd
- securitytracker.com/idnvd
- www.osvdb.org/25571nvd
- www.vupen.com/english/advisories/2006/1831nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/26494nvd
News mentions
0No linked articles in our index yet.