Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Alkacon OpenCms Multiple Input Validation Vulnerabilities

Alkacon OpenCms is prone to multiple input-validation vulnerabilities, including one cross-site scripting issue and a file-disclosure issue, because the application fails to properly sanitize user-supplied input.

Attackers can exploit these issues to steal cookie-based authentication credentials, to control how the site is rendered to the user, or to obtain information that could aid in further attacks.

OpenCms 7.0.3 is vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus