Описание
Alkacon OpenCMS Absolute Path Traversal via pathname in filePath.0 parameter
Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote authenticated administrators to read arbitrary files via a full pathname in the filePath.0 parameter.
Пакеты
Наименование
org.opencms:opencms-core
maven
Затронутые версииВерсия исправления
>= 7.0.3, < 7.0.5
7.0.5
Связанные уязвимости
nvd
больше 17 лет назад
Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote authenticated administrators to read arbitrary files via a full pathname in the filePath.0 parameter.