VulnerabilityModified
CVE-2010-2786
Directory traversal vulnerability in Piwik 0.6 through 0.6.3 allows remote attackers to include arbitrary local files and possibly have unspecified other impact via directory traversal sequences in a crafted data-renderer request.
MEDIUM 6.8EPSS 2.73%
Does this matter?
Lower severity and a low EPSS score (2.73%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in Piwik 0.6 through 0.6.3 allows remote attackers to include arbitrary local files and possibly have unspecified other impact via directory traversal sequences in a crafted data-renderer request.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.73% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- matomo/matomo
- Source
- secalert@redhat.com
References
- http://marc.info/?l=oss-security&m=128032989120346&w=2
- http://marc.info/?l=oss-security&m=128041221832498&w=2
- http://piwik.org/blog/2010/07/piwik-0-6-4-security-advisory/
- http://piwik.org/changelog/
- http://secunia.com/advisories/40703Vendor Advisory
- http://www.osvdb.org/66759
- http://www.securityfocus.com/bid/42031
- http://www.vupen.com/english/advisories/2010/1971Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60808
- http://marc.info/?l=oss-security&m=128032989120346&w=2
- http://marc.info/?l=oss-security&m=128041221832498&w=2
- http://piwik.org/blog/2010/07/piwik-0-6-4-security-advisory/
- http://piwik.org/changelog/
- http://secunia.com/advisories/40703Vendor Advisory
- http://www.osvdb.org/66759
- http://www.securityfocus.com/bid/42031
- http://www.vupen.com/english/advisories/2010/1971Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60808
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.