Resin Status Page Information Disclosure

This script is Copyright (C) 2003-2013 StrongHoldNet


Synopsis :

The remote web server is affected by an information disclosure issue.

Description :

Requesting the URI '/caucho-status' or '/server-status' gives
information about the currently running Resin java servlet container.

Solution :

If you don't use this feature, set the content of the
'<caucho-status>' element to 'false' in the resin.conf file.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)

Family: Web Servers

Nessus Plugin ID: 11930 ()

Bugtraq ID:

CVE ID: