4
CVSSv2

CVE-2006-3934

Published: 31/07/2006 Updated: 17/10/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Absolute path traversal vulnerability in downloadTrigger.jsp in Alkacon OpenCms prior to 6.2.2 allows remote authenticated users to download arbitrary files via an absolute pathname in the filePath parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

alkacon opencms 6.0.4

alkacon opencms 6.2

alkacon opencms 6.0.2

alkacon opencms 6.0.3

alkacon opencms 6.0.0

alkacon opencms