peter bassill · operator
$ cve CVE-2009-1510 JSON

CVE-2009-1510 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.2% (pctl 82)

Patch early

A public exploit exists.

Description

Multiple directory traversal vulnerabilities in KoschtIT Image Gallery 1.82 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the file parameter to (1) ki_makepic.php and (2) ki_nojsdisplayimage.php in ki_base/.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.25% — more likely to be exploited than 82% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2009-05-01
Last modified2026-06-16

Affected (1)

VendorProduct
koschtitkoschtit image gallery

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD