Cross-site scripting (XSS) vulnerability in the viewfile documentation command in Caucho Resin before 3.0.25, and 3.1.x before 3.1.4, allows remote attackers to inject arbitrary web script or HTML via the file parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/43367
http://www.vupen.com/english/advisories/2008/1930/references
http://www.securitytracker.com/id?1020372
http://www.securityfocus.com/bid/29948
http://www.kb.cert.org/vuls/id/305208
http://www.caucho.com/resin/changes/changes-31.xtp#3.1.4%20-%20Dec%205%2C%202007