UNKNOWN Maven
Alkacon OpenCMS Absolute Path Traversal via pathname in filePath.0 parameter
GHSA-xxjj-jhgc-r68f · CVE-2008-1301
Published · Modified
Description
Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote authenticated administrators to read arbitrary files via a full pathname in the filePath.0 parameter.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2008-1301
- WEB https://github.com/alkacon/opencms-core/commit/7b73b5559c1b025dfe0f7b38ed4119c25b9df409
- WEB https://exchange.xforce.ibmcloud.com/vulnerabilities/41096
- PACKAGE https://github.com/alkacon/opencms-core
- WEB http://securityreason.com/securityalert/3731
Ready to move
Start Securing
Free, no credit card | First findings in minutes