CVE Database
/

CVE-2009-10005

Back to search

CVE-2009-10005

Published: Aug 20, 2025

Modified: May 15, 2026

PUBLISHED

Description

ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 expose the mimencode binary via a CGI endpoint, allowing unauthenticated attackers to retrieve arbitrary files from the filesystem. By crafting a POST request to /cgi-bin/ck/mimencode with traversal and output parameters, attackers can read sensitive files such as /etc/passwd outside the webroot.

VendorProductVersions

ContentKeeper Technologies

Web Appliance

affected
0 - < 125.10

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2009-10005 - Security Vulnerability | QwikSec