peter bassill · operator
$ cve CVE-2009-0674 JSON

CVE-2009-0674 EXPLOIT

6.0
MEDIUM · CVSS 2.0 · EPSS 2.3% (pctl 83)

Patch early

A public exploit exists.

Description

images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows remote attackers to determine the existence of local files by sending requests with full pathnames in the aFonts array parameter, and then observing the error messages, which differ between existing and nonexistent pathnames.

Scoring

CVSS6.0 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
EPSS2.28% — more likely to be exploited than 83% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2009-02-22
Last modified2026-06-16

Affected (1)

VendorProduct
ravenphpscriptsravennuke

Public exploits

SourceTitleDate
exploit-dbravennuke 2.3.0 - Multiple Vulnerabilities2009-02-16

References

→ the Explorer  ·  watch your stack  ·  NVD