Resin WebServer break out of web root

    Resin Webserver


    Joe  Testa  found  following.   Resin  1.2.2  is  a  webserver.  A
    vulnerability exists which  allows a remote  user to break  out of
    the web root using relative paths (ie: '..', '...').

    Resin does in fact check  that the requested path lies  within the
    webroot, but by inserting a backslash before any '..' or '...', it
    is possible to defeat the  check.  The following URL  demonstrates
    this vulnerability:



    A fixed upgrade, 1.2.3, was released and is available at:

