CVE-2008-1301

Alkacon OpenCms <7.0.4 - Path Traversal

Title source: llm

Description

Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote authenticated administrators to read arbitrary files via a full pathname in the filePath.0 parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by nnposter · textwebappsphp
https://www.exploit-db.com/exploits/31366

Scores

EPSS 0.0312
EPSS Percentile 86.9%

Details

CWE
CWE-22
Status published
Products (3)
alkacon/opencms 7.0.3
alkacon/opencms 7.0.4
org.opencms/opencms-core 7.0.3 - 7.0.5Maven
Published Mar 12, 2008
Tracked Since Feb 18, 2026