GHSA-64hc-4jx3-62jp
Dashboard / Vulnerabilities / GHSA-64hc-4jx3-62jp
Summary: Alkacon OpenCMS Absolute Path Traversal via pathname in filePath parameter
Details: Absolute path traversal vulnerability in downloadTrigger.jsp in Alkacon OpenCms before 6.2.2 allows remote authenticated users to download arbitrary files via an absolute pathname in the filePath parameter.
References: https://nvd.nist.gov/vuln/detail/CVE-2006-3934, https://github.com/alkacon/opencms-core/commit/8f1c04c5a16fe8d0bdbd13b65bf2a7b5cf100ff9, https://exchange.xforce.ibmcloud.com/vulnerabilities/28000, https://github.com/alkacon/opencms-core, http://securityreason.com/securityalert/1302, http://www.opencms.org/export/download/opencms/opencms_6.2.2_src.zip, http://www.opencms.org/opencms/en/shownews.html?id=1002
Affected packages
Package
Name: org.opencms:opencms-core
Purl: pkg:maven/org.opencms/opencms-core
Affected ranges
Type: ECOSYSTEM
Events:
