Apache Cocoon contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a directory traversal attack on a sample script occurs, which will disclose filesystem file information resulting in a loss of confidentiality.
Classification
Attack Type:
Input Manipulation
Solution
Upgrade to version 2.1 or 2.2 (Development) after 22 Oct 2003 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround(s): remove all sample scripts, especially the view-source script.