Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request.Referenceshttp://www.securityfocus.com/bid/2533http://marc.info/?l=bugtraq&m=98633597813833&w=2