NONE · 0

CVE-2009-10005

ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 expose the mimencode binary via a CGI endpoint, allowing unauthenticated attackers to retrieve arbitrary files ...

Vulnerability Description

ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 expose the mimencode binary via a CGI endpoint, allowing unauthenticated attackers to retrieve arbitrary files from the filesystem. By crafting a POST request to /cgi-bin/ck/mimencode with traversal and output parameters, attackers can read sensitive files such as /etc/passwd outside the webroot.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-10005?

CVE-2009-10005 is a documented vulnerability. ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 expose the mimencode binary via a CGI endpoint, allowing unauthenticated attackers to retrieve arbitrary files ...

How severe is CVE-2009-10005?

CVSS scoring is not yet available for CVE-2009-10005. Check NVD for updates.

Is there a patch for CVE-2009-10005?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.