CVE-2006-3936
Summary
| CVE | CVE-2006-3936 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-31 22:04:00 UTC |
| Updated | 2018-10-17 21:32:00 UTC |
| Description | system/workplace/editors/editor.jsp in Alkacon OpenCms before 6.2.2 allows remote authenticated users to read the source code of arbitrary JSP files by specifying the file in the resource parameter, as demonstrated using index.jsp. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Alkacon | Opencms | 6.0.0 | All | All | All |
| Application | Alkacon | Opencms | 6.0.2 | All | All | All |
| Application | Alkacon | Opencms | 6.0.3 | All | All | All |
| Application | Alkacon | Opencms | 6.0.4 | All | All | All |
| Application | Alkacon | Opencms | 6.2 | All | All | All |
| Application | Alkacon | Opencms | 6.2.1 | All | All | All |
| Application | Alkacon | Opencms | 6.0.0 | All | All | All |
| Application | Alkacon | Opencms | 6.0.2 | All | All | All |
| Application | Alkacon | Opencms | 6.0.3 | All | All | All |
| Application | Alkacon | Opencms | 6.0.4 | All | All | All |
| Application | Alkacon | Opencms | 6.2 | All | All | All |
| Application | Alkacon | Opencms | 6.2.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple vulnerabilities in OpenCMS - CXSecurity.com | SREASON | securityreason.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Alkacon OpenCms Script Insertion and Authentication Bypass - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| www.opencms.org/export/download/opencms/opencms_6.2.2_src.zip | MISC | www.opencms.org | Patch |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Page not found - о0о Security Team | MISC | o0o.nu | Exploit |
| opencms.org: OpenCms news | MISC | www.opencms.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 997478 Java (Maven) Security Update for org.opencms:opencms-core (GHSA-c5vw-342h-x5rx)