4
CVSSv2

CVE-2006-3936

Published: 31/07/2006 Updated: 17/10/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

system/workplace/editors/editor.jsp in Alkacon OpenCms prior to 6.2.2 allows remote authenticated users to read the source code of arbitrary JSP files by specifying the file in the resource parameter, as demonstrated using index.jsp.

Vulnerable Product Search on Vulmon Subscribe to Product

alkacon opencms 6.2

alkacon opencms 6.2.1

alkacon opencms 6.0.3

alkacon opencms 6.0.4

alkacon opencms 6.0.0

alkacon opencms 6.0.2