Unrated severityNVD Advisory· Published Jul 26, 2014· Updated May 6, 2026
CVE-2014-2966
CVE-2014-2966
Description
The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism.
Affected products
4cpe:2.3:a:caucho:resin:*:*:*:*:professional:*:*:*+ 3 more
- cpe:2.3:a:caucho:resin:*:*:*:*:professional:*:*:*range: <=4.0.39
- cpe:2.3:a:caucho:resin:4.0.36:*:*:*:professional:*:*:*
- cpe:2.3:a:caucho:resin:4.0.37:*:*:*:professional:*:*:*
- cpe:2.3:a:caucho:resin:4.0.38:*:*:*:professional:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- caucho.com/products/resin/downloadnvdPatch
- www.kb.cert.org/vuls/id/162308nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.