ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful.
cve CVE-2009-20011 3 sources, 3 claims · Watch
NVD writes:
ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful. ContentKeeper Web Appliance (ahora mantenido por Impero Software) versiones anteriores a la 125.10 son vulnerables a la ej… the claim
ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful. ContentKeeper Web Appliance (ahora mantenido por Impero Software) versiones anteriores a la 125.10 son vulnerables a la ej… the claim
What it is to other things
In words only, so not counted until a person confirms one:
| affects | contentkeeper_technologies/contentkeeper_web_applianceNVD says “ContentKeeper Technologies · ContentKeeper Web Appliance” |
| made_by | contentkeeper_technologiesNVD says “ContentKeeper Technologies” |
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Cwe cwe | GitHub advisories | CWE-78receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2009-20011",
"cvss": {
"score": null,
"vector_string": null
},
"cvss_severities": {
"cvss_v3": {
"score": 0.0,
"vector_string": null
},
"cvss_v4": {
"score": 10.0,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-78",
"name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"
}
],
"description": "ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful.",
"epss": {
"percentage": 0.01358,
"percentile": 0.70511
},
"ghsa_id": "GHSA-w8w9-prcc-w4vw",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-w8w9-prcc-w4vw",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-w8w9-prcc-w4vw"
},
{
"type": "CVE",
"value": "CVE-2009-20011"
}
],
"nvd_published_at": "2025-08-30T14:15:35Z",
"published_at": "2026-10-02T00:31:21Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2009-20011",
"https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/http/contentkeeperweb_mimencode.rb",
"https://web.archive.org/web/20081220084819/http://www.contentkeeper.com",
"https://www.ativion.com/contentkeeper",
"https://www.vulncheck.com/advisories/contentkeeper-web-appliance-rce-via-mimencode",
"http://www.aushack.com/200904-contentkeeper.txt",
"https://github.com/advisories/GHSA-w8w9-prcc-w4vw"
],
"repository_advisory_url": null,
"severity": "critical",
"source_code_location": "",
"summary": "ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are...",
"type": "unreviewed",
"updated_at": "2026-10-02T00:31:28Z",
"url": "https://api.github.com/advisories/GHSA-w8w9-prcc-w4vw",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Platform platform | Metasploit exploit modules | Unixreceipt
What the source handed over{
"aliases": [],
"arch": "cmd",
"author": [
"aushack <patrick@osisecurity.com.au>"
],
"autofilter_ports": [],
"autofilter_services": [],
"check": true,
"default_credential": false,
"description": "This module exploits the ContentKeeper Web Appliance. Versions prior\n to 125.10 are affected. This module exploits a combination of weaknesses\n to enable remote command execution as the Apache user. By setting\n SkipEscalation to false, this module will attempt to setuid the bash shell.",
"disclosure_date": "2009-02-25",
"fullname": "exploit/unix/http/contentkeeperweb_mimencode",
"is_install_path": true,
"mod_time": "2026-04-22 11:59:31 +0000",
"name": "ContentKeeper Web Remote Command Execution",
"needs_cleanup": null,
"notes": {
"Reliability": [
"unknown-reliability"
],
"SideEffects": [
"unknown-side-effects"
],
"Stability": [
"unknown-stability"
]
},
"path": "/modules/exploits/unix/http/contentkeeperweb_mimencode.rb",
"platform": "Unix",
"post_auth": false,
"rank": 600,
"ref_name": "unix/http/contentkeeperweb_mimencode",
"references": [
"CVE-2009-20011",
"OSVDB-54551",
"OSVDB-54552",
"URL-http://www.aushack.com/200904-contentkeeper.txt"
],
"rport": 80,
"session_types": false,
"targets": [
"Automatic"
],
"type": "exploit"
} | — |
| Product product | NVD | ContentKeeper Web Appliancereceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"modules": [
"mimencode CGI handler",
"/cgi-bin/ck/mimencode"
],
"product": "ContentKeeper Web Appliance",
"vendor": "ContentKeeper Technologies",
"versions": [
{
"lessThan": "125.10",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"source": "disclosure@vulncheck.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful."
},
{
"lang": "es",
"value": "ContentKeeper Web Appliance (ahora mantenido por Impero Software) versiones anteriores a la 125.10 son vulnerables a la ejecución remota de comandos debido al manejo inseguro de cargas de archivos a través de la utilidad CGI mimencode. La vulnerabilidad permite a atacantes no autenticados cargar y ejecutar scripts arbitrarios como el usuario Apache. Además, el exploit puede escalar privilegios opcionalmente abusando del uso inseguro de PATH en el binario benetool, lo que resulta en acceso a nivel de root si tiene éxito."
}
],
"id": "CVE-2009-20011",
"lastModified": "2026-10-01T23:10:00.233",
"metrics": {
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 10.0,
"baseSeverity": "CRITICAL",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2009-20011",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-09-02T20:42:55.453012Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-08-30T14:15:35.140",
"references": [
{
"source": "disclosure@vulncheck.com",
"url": "http://www.aushack.com/200904-contentkeeper.txt"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/http/contentkeeperweb_mimencode.rb"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://web.archive.org/web/20081220084819/http://www.contentkeeper.com/"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://www.ativion.com/contentkeeper/"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://www.vulncheck.com/advisories/contentkeeper-web-appliance-rce-via-mimencode"
}
],
"sourceIdentifier": "disclosure@vulncheck.com",
"vulnStatus": "Deferred",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-78"
},
{
"lang": "en",
"value": "CWE-434"
}
],
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
]
}
} | — |
| Rank rank | Metasploit exploit modules | 600 Excellent. Cannot crash the service. A memory-corruption exploit does not qualify. receipt
What the source handed over{
"aliases": [],
"arch": "cmd",
"author": [
"aushack <patrick@osisecurity.com.au>"
],
"autofilter_ports": [],
"autofilter_services": [],
"check": true,
"default_credential": false,
"description": "This module exploits the ContentKeeper Web Appliance. Versions prior\n to 125.10 are affected. This module exploits a combination of weaknesses\n to enable remote command execution as the Apache user. By setting\n SkipEscalation to false, this module will attempt to setuid the bash shell.",
"disclosure_date": "2009-02-25",
"fullname": "exploit/unix/http/contentkeeperweb_mimencode",
"is_install_path": true,
"mod_time": "2026-04-22 11:59:31 +0000",
"name": "ContentKeeper Web Remote Command Execution",
"needs_cleanup": null,
"notes": {
"Reliability": [
"unknown-reliability"
],
"SideEffects": [
"unknown-side-effects"
],
"Stability": [
"unknown-stability"
]
},
"path": "/modules/exploits/unix/http/contentkeeperweb_mimencode.rb",
"platform": "Unix",
"post_auth": false,
"rank": 600,
"ref_name": "unix/http/contentkeeperweb_mimencode",
"references": [
"CVE-2009-20011",
"OSVDB-54551",
"OSVDB-54552",
"URL-http://www.aushack.com/200904-contentkeeper.txt"
],
"rport": 80,
"session_types": false,
"targets": [
"Automatic"
],
"type": "exploit"
} | — |
| Severity severity | GitHub advisories | critical GitHub's own rating, from the CVSS base score at 9.0 and above. receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2009-20011",
"cvss": {
"score": null,
"vector_string": null
},
"cvss_severities": {
"cvss_v3": {
"score": 0.0,
"vector_string": null
},
"cvss_v4": {
"score": 10.0,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-78",
"name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"
}
],
"description": "ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful.",
"epss": {
"percentage": 0.01358,
"percentile": 0.70511
},
"ghsa_id": "GHSA-w8w9-prcc-w4vw",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-w8w9-prcc-w4vw",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-w8w9-prcc-w4vw"
},
{
"type": "CVE",
"value": "CVE-2009-20011"
}
],
"nvd_published_at": "2025-08-30T14:15:35Z",
"published_at": "2026-10-02T00:31:21Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2009-20011",
"https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/http/contentkeeperweb_mimencode.rb",
"https://web.archive.org/web/20081220084819/http://www.contentkeeper.com",
"https://www.ativion.com/contentkeeper",
"https://www.vulncheck.com/advisories/contentkeeper-web-appliance-rce-via-mimencode",
"http://www.aushack.com/200904-contentkeeper.txt",
"https://github.com/advisories/GHSA-w8w9-prcc-w4vw"
],
"repository_advisory_url": null,
"severity": "critical",
"source_code_location": "",
"summary": "ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are...",
"type": "unreviewed",
"updated_at": "2026-10-02T00:31:28Z",
"url": "https://api.github.com/advisories/GHSA-w8w9-prcc-w4vw",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Status status | NVD | Deferredreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"modules": [
"mimencode CGI handler",
"/cgi-bin/ck/mimencode"
],
"product": "ContentKeeper Web Appliance",
"vendor": "ContentKeeper Technologies",
"versions": [
{
"lessThan": "125.10",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"source": "disclosure@vulncheck.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful."
},
{
"lang": "es",
"value": "ContentKeeper Web Appliance (ahora mantenido por Impero Software) versiones anteriores a la 125.10 son vulnerables a la ejecución remota de comandos debido al manejo inseguro de cargas de archivos a través de la utilidad CGI mimencode. La vulnerabilidad permite a atacantes no autenticados cargar y ejecutar scripts arbitrarios como el usuario Apache. Además, el exploit puede escalar privilegios opcionalmente abusando del uso inseguro de PATH en el binario benetool, lo que resulta en acceso a nivel de root si tiene éxito."
}
],
"id": "CVE-2009-20011",
"lastModified": "2026-10-01T23:10:00.233",
"metrics": {
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 10.0,
"baseSeverity": "CRITICAL",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2009-20011",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-09-02T20:42:55.453012Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-08-30T14:15:35.140",
"references": [
{
"source": "disclosure@vulncheck.com",
"url": "http://www.aushack.com/200904-contentkeeper.txt"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/http/contentkeeperweb_mimencode.rb"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://web.archive.org/web/20081220084819/http://www.contentkeeper.com/"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://www.ativion.com/contentkeeper/"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://www.vulncheck.com/advisories/contentkeeper-web-appliance-rce-via-mimencode"
}
],
"sourceIdentifier": "disclosure@vulncheck.com",
"vulnStatus": "Deferred",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-78"
},
{
"lang": "en",
"value": "CWE-434"
}
],
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
]
}
} | — |
| Vendor vendor | NVD | ContentKeeper Technologiesreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"modules": [
"mimencode CGI handler",
"/cgi-bin/ck/mimencode"
],
"product": "ContentKeeper Web Appliance",
"vendor": "ContentKeeper Technologies",
"versions": [
{
"lessThan": "125.10",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"source": "disclosure@vulncheck.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful."
},
{
"lang": "es",
"value": "ContentKeeper Web Appliance (ahora mantenido por Impero Software) versiones anteriores a la 125.10 son vulnerables a la ejecución remota de comandos debido al manejo inseguro de cargas de archivos a través de la utilidad CGI mimencode. La vulnerabilidad permite a atacantes no autenticados cargar y ejecutar scripts arbitrarios como el usuario Apache. Además, el exploit puede escalar privilegios opcionalmente abusando del uso inseguro de PATH en el binario benetool, lo que resulta en acceso a nivel de root si tiene éxito."
}
],
"id": "CVE-2009-20011",
"lastModified": "2026-10-01T23:10:00.233",
"metrics": {
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 10.0,
"baseSeverity": "CRITICAL",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2009-20011",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-09-02T20:42:55.453012Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-08-30T14:15:35.140",
"references": [
{
"source": "disclosure@vulncheck.com",
"url": "http://www.aushack.com/200904-contentkeeper.txt"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/http/contentkeeperweb_mimencode.rb"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://web.archive.org/web/20081220084819/http://www.contentkeeper.com/"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://www.ativion.com/contentkeeper/"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://www.vulncheck.com/advisories/contentkeeper-web-appliance-rce-via-mimencode"
}
],
"sourceIdentifier": "disclosure@vulncheck.com",
"vulnStatus": "Deferred",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-78"
},
{
"lang": "en",
"value": "CWE-434"
}
],
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
]
}
} | — |
vulnerability
| ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful. zetlyn/cve-nvd · 2025-08-30 | product ContentKeeper Web Appliance status Deferred vendor ContentKeeper Technologies | source |
| ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are... zetlyn/cve-ghsa · 2026-10-02 | cwe CWE-78 severity critical | source |
exploit
| ContentKeeper Web Remote Command Execution zetlyn/cve-metasploit · 2009-02-25 | platform Unix rank 600 | source |