CVE-2019-13237
CVE-2019-13237
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/settings/index.jsp.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencepacketstormsecurity.com/files/154281/Alkacon-OpenCMS-10.5.x-Local-File-Inclusion.htmlunverifiedexploitdbwww.exploit-db.com/exploits/47340unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →