Absolute path traversal vulnerability in downloadTrigger.jsp in Alkacon OpenCms before 6.2.2 allows remote authenticated users to download arbitrary files via an absolute pathname in the filePath parameter.
- http://o0o.nu/~meder/OpenCMS_multiple_vulnerabilities.txt
- http://securityreason.com/securityalert/1302
No PoCs found on GitHub currently.