CVE-2008-1301
Alkacon OpenCms <7.0.4 - Path Traversal
Title source: llmDescription
Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote authenticated administrators to read arbitrary files via a full pathname in the filePath.0 parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by nnposter · textwebappsphp
https://www.exploit-db.com/exploits/31366
References (5)
Scores
EPSS
0.0312
EPSS Percentile
86.9%
Details
CWE
CWE-22
Status
published
Products (3)
alkacon/opencms
7.0.3
alkacon/opencms
7.0.4
org.opencms/opencms-core
7.0.3 - 7.0.5Maven
Published
Mar 12, 2008
Tracked Since
Feb 18, 2026