← Vulnerability feed

Vulnerability record · CVE-2012-2968 · published 12 August 2012

CVE-2012-2968: Caucho resin path traversal vulnerability

Caucho · Resin

Directory traversal vulnerability in Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to create files in arbitrary directories via a .. (dot dot) in a pathname within an HTTP request.

5.0 CVSS 2.0 Medium EPSS 3.5% · top 11.3% CWE-22 · Path traversal
5.0CVSS 2.0 base score
3.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to create files in arbitrary directories via a .. (dot dot) in a pathname within an HTTP request.

AV:N/AC:L/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-2968 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2021-44138Caucho resin path traversal vulnerabilityThere is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in…EPSS 12%7.5CVE-2012-2965Caucho resin improper input validation vulnerabilityCaucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of variables, which has unknown i…EPSS 1.6%7.5CVE-2012-2966Caucho resin vulnerabilityCaucho Quercus, as distributed in Resin before 4.0.29, overwrites entries in the SERVER superglobal array on the basis of POST parameters, which has …EPSS 1.6%7.5CVE-2012-2967Caucho resin vulnerabilityCaucho Quercus, as distributed in Resin before 4.0.29, does not properly implement the == (equals sign equals sign) operator for comparisons, which h…EPSS 1.6%6.4CVE-2012-2969Caucho resin permissions and access controls vulnerabilityCaucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filename extensions for created fil…EPSS 3.5%5.0CVE-2014-2966Caucho resin improper input validation vulnerabilityThe ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended…EPSS 1.7%5.0CVE-2004-0281Caucho resin vulnerabilityCaucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP req…EPSS 4.2%4.3CVE-2010-2032Caucho resin cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possi…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2012-2968), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.