CVE-2006-3936

EPSS 0.64%

Alkacon OpenCms Exposes JSP Source Code

發布日:2022/5/1修改日:2024/2/12

描述

`system/workplace/editors/editor.jsp` in Alkacon OpenCms before 6.2.2 allows remote authenticated users to read the source code of arbitrary JSP files by specifying the file in the resource parameter, as demonstrated using `index.jsp`.

受影響套件(1)

參考連結(6)