peter bassill · operator
$ cve CVE-2010-2676 JSON

CVE-2010-2676 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 2.9% (pctl 86)

Patch early

A public exploit exists.

Description

Multiple directory traversal vulnerabilities in index.php in Open Web Analytics (OWA) 1.2.3 might allow remote attackers to read arbitrary files via directory traversal sequences in the (1) owa_action and (2) owa_do parameters.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS2.86% — more likely to be exploited than 86% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2010-07-08
Last modified2026-06-16

Affected (1)

VendorProduct
openwebanalyticsopen web analytics

Public exploits

SourceTitleDate
exploit-dbOpen Web Analytics 1.2.3 - Multiple File Inclusions2010-03-27

References

→ the Explorer  ·  watch your stack  ·  NVD