Vulnerability Description
The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Caucho | Resin | <= 4.0.39 |
Related Weaknesses (CWE)
References
- http://caucho.com/products/resin/download#downloadPatch
- http://www.kb.cert.org/vuls/id/162308Third Party AdvisoryUS Government Resource
- http://caucho.com/products/resin/download#downloadPatch
- http://www.kb.cert.org/vuls/id/162308Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2014-2966?
CVE-2014-2966 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demon...
How severe is CVE-2014-2966?
CVE-2014-2966 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-2966?
Check the references section above for vendor advisories and patch information. Affected products include: Caucho Resin.