CVE-2006-3936

EPSS 0.64%

Alkacon OpenCms Exposes JSP Source Code

Published: 5/1/2022Modified: 2/12/2024

Description

`system/workplace/editors/editor.jsp` in Alkacon OpenCms before 6.2.2 allows remote authenticated users to read the source code of arbitrary JSP files by specifying the file in the resource parameter, as demonstrated using `index.jsp`.

Affected packages (1)

References (6)