CVE-2009-2552 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 2% (pctl 80)
Patch early
A public exploit exists.
Description
Multiple directory traversal vulnerabilities in comments.php in Super Simple Blog Script 2.5.4 allow remote attackers to overwrite, include, and execute arbitrary local files via the entry parameter.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 1.98% — more likely to be exploited than 80% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-07-20 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| supersimple | super simple blog script |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Super Simple Blog Script 2.5.4 - Local File Inclusion | 2009-07-17 |
References
→ the Explorer · watch your stack · NVD