Unrated severityNVD Advisory· Published May 16, 2007· Updated Apr 23, 2026
CVE-2007-2440
CVE-2007-2440
Description
Directory traversal vulnerability in Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to read certain files via a .. (dot dot) in a URI containing a "\web-inf" sequence.
Affected products
2cpe:2.3:a:caucho_technology:resin:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:caucho_technology:resin:*:*:*:*:*:*:*:*range: <=3.1.0
- cpe:2.3:a:caucho_technology:resin:*:*:professional_windows:*:*:*:*:*range: <=3.1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- secunia.com/advisories/25286nvdPatchVendor Advisory
- www.rapid7.com/advisories/R7-0029.jspnvdPatchVendor Advisory
- www.securityfocus.com/bid/23985nvdExploitPatch
- osvdb.org/36058nvd
- www.caucho.com/resin-3.1/changes/changes.xtpnvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2007/1824nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/34296nvd
News mentions
0No linked articles in our index yet.