CVE Vulnerabilities

CVE-2006-3936

Published: Jul 31, 2006 | Modified: Oct 17, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

system/workplace/editors/editor.jsp in Alkacon OpenCms before 6.2.2 allows remote authenticated users to read the source code of arbitrary JSP files by specifying the file in the resource parameter, as demonstrated using index.jsp.

Affected Software

Name Vendor Start Version End Version
Opencms Alkacon 6.0.0 (including) 6.0.0 (including)
Opencms Alkacon 6.0.2 (including) 6.0.2 (including)
Opencms Alkacon 6.0.3 (including) 6.0.3 (including)
Opencms Alkacon 6.0.4 (including) 6.0.4 (including)
Opencms Alkacon 6.2 (including) 6.2 (including)
Opencms Alkacon 6.2.1 (including) 6.2.1 (including)

References