peter bassill · operator
$ cve CVE-2009-2544 JSON

CVE-2009-2544 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 3.4% (pctl 89)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in the Marcelo Costa FileServer component 1.0 for Microsoft Windows Live Messenger and Messenger Plus! Live (MPL) allows remote authenticated users to list arbitrary directories and read arbitrary files via a .. (dot dot) in a pathname.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
EPSS3.43% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2009-07-20
Last modified2026-06-16

Affected (3)

VendorProduct
marcelo costafileserver
microsoftmessenger plus\! live
microsoftwindows live messenger

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD