CVE-2014-2966
The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0040 (0.4%)
Percentile: 60.5%
EPSS: 2026-05-06
Affects
caucho:resinTechnical description
The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism.
Published: 7/26/2014, 3:55:03 PM
Last modified: 5/6/2026, 10:30:45 PM