Vulnerabilities > CVE-2006-3936 - Unspecified vulnerability in Alkacon Opencms
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN alkacon
nessus
Summary
system/workplace/editors/editor.jsp in Alkacon OpenCms before 6.2.2 allows remote authenticated users to read the source code of arbitrary JSP files by specifying the file in the resource parameter, as demonstrated using index.jsp.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Nessus
NASL family | CGI abuses |
NASL id | OPENCMS_622.NASL |
description | The remote host is running OpenCms, a Java-based content management system. According to its banner, the version of OpenCms installed on the remote host reportedly allows authenticated users to upload OpenCms modules and database import/export files, download arbitrary files, send messages to all users, and launch cross-site scripting attacks. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22093 |
published | 2006-07-27 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22093 |
title | OpenCms < 6.2.2 Multiple Vulnerabilities |
code |
|
References
- http://o0o.nu/~meder/OpenCMS_multiple_vulnerabilities.txt
- http://o0o.nu/~meder/OpenCMS_multiple_vulnerabilities.txt
- http://secunia.com/advisories/21193
- http://secunia.com/advisories/21193
- http://securityreason.com/securityalert/1302
- http://securityreason.com/securityalert/1302
- http://www.opencms.org/export/download/opencms/opencms_6.2.2_src.zip
- http://www.opencms.org/export/download/opencms/opencms_6.2.2_src.zip
- http://www.opencms.org/opencms/en/shownews.html?id=1002
- http://www.opencms.org/opencms/en/shownews.html?id=1002
- http://www.securityfocus.com/archive/1/441182/100/0/threaded
- http://www.securityfocus.com/archive/1/441182/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28001
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28001