peter bassill · operator
$ cve CVE-2009-2397 JSON

CVE-2009-2397 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 2.9% (pctl 87)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in download.php in Audio Article Directory allows remote attackers to read arbitrary files via directory traversal sequences in the file parameter.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS2.92% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2009-07-09
Last modified2026-06-16

Affected (1)

VendorProduct
audioarticledirectoryaudio article directory

Public exploits

SourceTitleDate
exploit-dbAudio Article Directory - 'file' Remote File Disclosure2009-06-29

References

→ the Explorer  ·  watch your stack  ·  NVD