VulnerabilityModified
CVE-2009-0929
Directory traversal vulnerability in the media manager in Nucleus CMS before 3.40 allows remote attackers to read arbitrary files via unknown vectors.
MEDIUM 5.0EPSS 1.60%
Does this matter?
Lower severity and a low EPSS score (1.60%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in the media manager in Nucleus CMS before 3.40 allows remote attackers to read arbitrary files via unknown vectors.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.60% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- nucleus group/nucleus cms
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/34180Vendor Advisory
- http://www.nucleuscms.org/index.php/item/index.php/item/3051Vendor Advisory
- http://www.securityfocus.com/bid/34040
- http://www.vupen.com/english/advisories/2009/0637
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49142
- http://secunia.com/advisories/34180Vendor Advisory
- http://www.nucleuscms.org/index.php/item/index.php/item/3051Vendor Advisory
- http://www.securityfocus.com/bid/34040
- http://www.vupen.com/english/advisories/2009/0637
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49142
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.