4
CVE-2006-3936
- EPSS 1.35%
- Veröffentlicht 31.07.2006 22:04:00
- Zuletzt bearbeitet 16.06.2026 22:28:06
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
system/workplace/editors/editor.jsp in Alkacon OpenCms before 6.2.2 allows remote authenticated users to read the source code of arbitrary JSP files by specifying the file in the resource parameter, as demonstrated using index.jsp.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.35% | 0.679 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
http://o0o.nu/~meder/OpenCMS_multiple_vulnerabilities.txt
http://secunia.com/advisories/21193
http://securityreason.com/securityalert/1302
http://www.opencms.org/export/download/opencms/opencms_6.2.2_src.zip
http://www.opencms.org/opencms/en/shownews.html?id=1002
http://www.securityfocus.com/archive/1/441182/100/0/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/28001