Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Absolute path traversal vulnerability in downloadTrigger.jsp in Alkacon OpenCms before 6.2.2 allows remote authenticated users to download arbitrary files via an absolute pathname in the filePath parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Alkacon OpenCms 'downloadTrigger.jsp' 绝对路径遍历漏洞
Vulnerability Description
Alkacon OpenCms 6.2.2之前版本中的downloadTrigger.jsp存在绝对路径遍历漏洞。 远程认证用户可以借助filePath参数中的绝对路径名,下载任意文件。
CVSS Information
N/A
Vulnerability Type
N/A