CVE-2009-2109 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 9.5% (pctl 95)
Patch early
A public exploit exists.
Description
Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (1) language parameter to charts.php and the (2) fretsweb_language cookie parameter to unspecified vectors, possibly related to admin/common.php.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 9.48% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-06-18 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| fretsweb project | fretsweb |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | FretsWeb 1.2 - Multiple Local File Inclusions | 2009-06-17 |
References
→ the Explorer · watch your stack · NVD