PoC Index

CVE-2008-1301

MEDIUM 4.6EPSS 2.3%

Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote authenticated administrators to read arbitrary files via a full pathname in the filePath.0 parameter.

CVSS v4.0
4.6 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
CVSS v2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS
2.25% chance of exploitation in the next 30 days, 82th percentile
Published
2008-03-12
Updated
2024-08-07

ExploitDB entries (1)

References

Related