5
CVSSv2

CVE-2009-1085

Published: 25/03/2009 Updated: 21/11/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Piwik 0.2.32 and previous versions stores sensitive information under the web root with insufficient access control, which allows remote malicious users to obtain the API key and other sensitive information via a direct request for misc/cron/archive.sh.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

matomo matomo 0.2.30

matomo matomo 0.2.29

matomo matomo 0.2.28

matomo matomo 0.2.27

matomo matomo 0.2.25

matomo matomo

matomo matomo 0.2.26

matomo matomo 0.2.31