CVE-2009-1085
Published Mar 25, 2009
Last updated 5 years ago
Overview
- Description
- Piwik 0.2.32 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the API key and other sensitive information via a direct request for misc/cron/archive.sh.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:matomo:matomo:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "43A7DB24-9CF1-4F80-AC3B-770416688084", "versionEndIncluding": "0.2.32" }, { "criteria": "cpe:2.3:a:matomo:matomo:0.2.25:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "262A0DB0-6CE4-41E7-BDC6-18924C76EDCB" }, { "criteria": "cpe:2.3:a:matomo:matomo:0.2.26:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D3F37F31-2288-4B86-9EEB-38EE8B1979C2" }, { "criteria": "cpe:2.3:a:matomo:matomo:0.2.27:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "74DBC09F-4B09-490B-8367-93B3257F9DBF" }, { "criteria": "cpe:2.3:a:matomo:matomo:0.2.28:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0384553E-FEEB-4AE4-B1F1-1EC99BE07BD9" }, { "criteria": "cpe:2.3:a:matomo:matomo:0.2.29:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E64C21FE-BCA5-4830-AA85-5959CBE3800D" }, { "criteria": "cpe:2.3:a:matomo:matomo:0.2.30:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BF976D83-866E-416D-A21C-2BF2A8F95462" }, { "criteria": "cpe:2.3:a:matomo:matomo:0.2.31:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1E9EB7C0-C645-4E1A-A7CD-87325BBA81E5" } ], "operator": "OR" } ] } ]