Alfresco - '/cmisbrowser?url' Server-Side Request Forgery

Related Vulnerabilities: CVE-2014-9302  
Publish Date: 16 Jul 2014
Author: V. Paulikas
                							

                source: http://www.securityfocus.com/bid/68/info

http://www.example.com/alfresco/proxy?endpoint=http://internal_system:port 663/info
 
Alfresco Community Edition is prone to multiple security vulnerabilities.
 
An attacker may leverage these issues to gain sensitive information or bypass certain security restrictions.
 
Alfresco Community Edition 4.2.f and earlier are vulnerable. 

http://www.example.com/alfresco/cmisbrowser?url=http://internal_system:port