Resin < Viewfile file Parameter XSS
Medium Nessus Network Monitor Plugin ID 4561
SynopsisThe remote host is vulnerable to a cross-site scripting (XSS) attack.
DescriptionThe remote web server is running Resin.
This version of Resin is vulnerable to a cross-site scripting flaw via the 'file' parameter of the Viewfile application. An attacker exploiting this flaw would be able to execute arbitrary script code in the browsers of other Resin users.
SolutionUpgrade to version 3.0.25, 3.1.4 or higher.