CVE-2010-2676 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 2.9% (pctl 86)
Patch early
A public exploit exists.
Description
Multiple directory traversal vulnerabilities in index.php in Open Web Analytics (OWA) 1.2.3 might allow remote attackers to read arbitrary files via directory traversal sequences in the (1) owa_action and (2) owa_do parameters.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 2.86% — more likely to be exploited than 86% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-07-08 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| openwebanalytics | open web analytics |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Open Web Analytics 1.2.3 - Multiple File Inclusions | 2010-03-27 |
References
- http://packetstormsecurity.org/1003-exploits/owa123-lfirfi.txt
- http://www.ITSecTeam.com/en/vulnerabilities/vulnerability26.htm
- http://www.exploit-db.com/exploits/11903
- http://www.openwebanalytics.com/?p=87
- https://exchange.xforce.ibmcloud.com/vulnerabilities/57240
- http://packetstormsecurity.org/1003-exploits/owa123-lfirfi.txt
- http://www.ITSecTeam.com/en/vulnerabilities/vulnerability26.htm
- http://www.exploit-db.com/exploits/11903
- http://www.openwebanalytics.com/?p=87
- https://exchange.xforce.ibmcloud.com/vulnerabilities/57240
→ the Explorer · watch your stack · NVD