CVE-2006-3936
Alkacon OpenCms Exposes JSP Source Code
EPSS 0.64%
Description
`system/workplace/editors/editor.jsp` in Alkacon OpenCms before 6.2.2 allows remote authenticated users to read the source code of arbitrary JSP files by specifying the file in the resource parameter, as demonstrated using `index.jsp`.
How to fix CVE-2006-3936
To remediate CVE-2006-3936, upgrade the affected package to a fixed version below.
- Maven/org.opencms:opencms-core—upgrade to 6.2.2 or later
Is CVE-2006-3936 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 6.2.2