First published: Mon Jul 31 2006(Updated: )
`system/workplace/editors/editor.jsp` in Alkacon OpenCms before 6.2.2 allows remote authenticated users to read the source code of arbitrary JSP files by specifying the file in the resource parameter, as demonstrated using `index.jsp`.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alkacon OpenCMS | =6.0.3 | |
Alkacon OpenCMS | =6.0.4 | |
Alkacon OpenCMS | =6.0.0 | |
Alkacon OpenCMS | =6.2 | |
Alkacon OpenCMS | =6.0.2 | |
Alkacon OpenCMS | =6.2.1 | |
maven/org.opencms:opencms-core | <6.2.2 | 6.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.