{"id":"CVE-2006-3935","aliases":[],"url":"https://o3.security/vulnerability/CVE-2006-3935","summary":"Alkacon OpenCMS Improper Access Control via system/workplace/views/admin/admin-main.jsp","details":"system/workplace/views/admin/admin-main.jsp in Alkacon OpenCms before 6.2.2 does not restrict access to administrator functions, which allows remote authenticated users to (1) send broadcast messages to all users (/workplace/broadcast), (2) list all users (/accounts/users), (3) add webusers (/accounts/webusers/new), (4) upload database import and export files (/database/importhttp), (5) upload arbitrary program modules (/modules/modules_import), and (6) read the log file (/workplace/logfileview) by setting the appropriate value for the path parameter in a direct request to admin-main.jsp.","published":"2022-05-01T07:13:46Z","modified":"2025-06-20T16:29:48.832158Z","cvss":null,"epss":{"score":0.01811,"percentile":0.76957,"asOf":"2026-08-22"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.opencms:opencms-core","fixedVersion":"6.2.2"}],"fix":{"url":"https://github.com/alkacon/opencms-core/commit/8f1c04c5a16fe8d0bdbd13b65bf2a7b5cf100ff9","label":"alkacon/opencms-core@8f1c04c"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2006-3935"},{"type":"WEB","url":"https://github.com/alkacon/opencms-core/commit/8f1c04c5a16fe8d0bdbd13b65bf2a7b5cf100ff9"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27996"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28003"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28010"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28026"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28031"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28036"},{"type":"PACKAGE","url":"https://github.com/alkacon/opencms-core"},{"type":"WEB","url":"http://www.opencms.org/export/download/opencms/opencms_6.2.2_src.zip"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-06-20T16:29:48.832158Z"}}