peter bassill · operator
$ cve CVE-2009-2109 JSON

CVE-2009-2109 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 9.5% (pctl 95)

Patch early

A public exploit exists.

Description

Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (1) language parameter to charts.php and the (2) fretsweb_language cookie parameter to unspecified vectors, possibly related to admin/common.php.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS9.48% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2009-06-18
Last modified2026-06-16

Affected (1)

VendorProduct
fretsweb projectfretsweb

Public exploits

SourceTitleDate
exploit-dbFretsWeb 1.2 - Multiple Local File Inclusions2009-06-17

References

→ the Explorer  ·  watch your stack  ·  NVD