Zetlyn

ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful.

cve CVE-2009-20011 3 sources, 3 claims · Watch

NVD writes:
ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful. ContentKeeper Web Appliance (ahora mantenido por Impero Software) versiones anteriores a la 125.10 son vulnerables a la ej… the claim

What it is to other things

In words only, so not counted until a person confirms one:

affectscontentkeeper_technologies/contentkeeper_web_appliance
NVD says “ContentKeeper Technologies · ContentKeeper Web Appliance”
made_bycontentkeeper_technologies
NVD says “ContentKeeper Technologies”

What each source says

PropertySourceSaidMeans here
Cwe
cwe
GitHub advisoriesCWE-78
receipt
Source
GitHub advisories
Its words
CWE-78
Read by
field:cwes[].cwe_id
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-02 12:00 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2009-20011",
  "cvss": {
    "score": null,
    "vector_string": null
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 0.0,
      "vector_string": null
    },
    "cvss_v4": {
      "score": 10.0,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-78",
      "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"
    }
  ],
  "description": "ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful.",
  "epss": {
    "percentage": 0.01358,
    "percentile": 0.70511
  },
  "ghsa_id": "GHSA-w8w9-prcc-w4vw",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-w8w9-prcc-w4vw",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-w8w9-prcc-w4vw"
    },
    {
      "type": "CVE",
      "value": "CVE-2009-20011"
    }
  ],
  "nvd_published_at": "2025-08-30T14:15:35Z",
  "published_at": "2026-10-02T00:31:21Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2009-20011",
    "https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/http/contentkeeperweb_mimencode.rb",
    "https://web.archive.org/web/20081220084819/http://www.contentkeeper.com",
    "https://www.ativion.com/contentkeeper",
    "https://www.vulncheck.com/advisories/contentkeeper-web-appliance-rce-via-mimencode",
    "http://www.aushack.com/200904-contentkeeper.txt",
    "https://github.com/advisories/GHSA-w8w9-prcc-w4vw"
  ],
  "repository_advisory_url": null,
  "severity": "critical",
  "source_code_location": "",
  "summary": "ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are...",
  "type": "unreviewed",
  "updated_at": "2026-10-02T00:31:28Z",
  "url": "https://api.github.com/advisories/GHSA-w8w9-prcc-w4vw",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Platform
platform
Metasploit exploit modulesUnix
receipt
Source
Metasploit exploit modules
Its words
Unix
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 12:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd",
  "author": [
    "aushack <patrick@osisecurity.com.au>"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "This module exploits the ContentKeeper Web Appliance. Versions prior\n          to 125.10 are affected. This module exploits a combination of weaknesses\n          to enable remote command execution as the Apache user. By setting\n          SkipEscalation to false, this module will attempt to setuid the bash shell.",
  "disclosure_date": "2009-02-25",
  "fullname": "exploit/unix/http/contentkeeperweb_mimencode",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:59:31 +0000",
  "name": "ContentKeeper Web Remote Command Execution",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "unknown-reliability"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "unknown-stability"
    ]
  },
  "path": "/modules/exploits/unix/http/contentkeeperweb_mimencode.rb",
  "platform": "Unix",
  "post_auth": false,
  "rank": 600,
  "ref_name": "unix/http/contentkeeperweb_mimencode",
  "references": [
    "CVE-2009-20011",
    "OSVDB-54551",
    "OSVDB-54552",
    "URL-http://www.aushack.com/200904-contentkeeper.txt"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "Automatic"
  ],
  "type": "exploit"
}
—
Product
product
NVDContentKeeper Web Appliance
receipt
Source
NVD
Its words
ContentKeeper Web Appliance
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "mimencode CGI handler",
              "/cgi-bin/ck/mimencode"
            ],
            "product": "ContentKeeper Web Appliance",
            "vendor": "ContentKeeper Technologies",
            "versions": [
              {
                "lessThan": "125.10",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful."
      },
      {
        "lang": "es",
        "value": "ContentKeeper Web Appliance (ahora mantenido por Impero Software) versiones anteriores a la 125.10 son vulnerables a la ejecución remota de comandos debido al manejo inseguro de cargas de archivos a través de la utilidad CGI mimencode. La vulnerabilidad permite a atacantes no autenticados cargar y ejecutar scripts arbitrarios como el usuario Apache. Además, el exploit puede escalar privilegios opcionalmente abusando del uso inseguro de PATH en el binario benetool, lo que resulta en acceso a nivel de root si tiene éxito."
      }
    ],
    "id": "CVE-2009-20011",
    "lastModified": "2026-10-01T23:10:00.233",
    "metrics": {
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 10.0,
            "baseSeverity": "CRITICAL",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "HIGH",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2009-20011",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-09-02T20:42:55.453012Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-30T14:15:35.140",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "http://www.aushack.com/200904-contentkeeper.txt"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/http/contentkeeperweb_mimencode.rb"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://web.archive.org/web/20081220084819/http://www.contentkeeper.com/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.ativion.com/contentkeeper/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/contentkeeper-web-appliance-rce-via-mimencode"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-78"
          },
          {
            "lang": "en",
            "value": "CWE-434"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Rank
rank
Metasploit exploit modules600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 12:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd",
  "author": [
    "aushack <patrick@osisecurity.com.au>"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "This module exploits the ContentKeeper Web Appliance. Versions prior\n          to 125.10 are affected. This module exploits a combination of weaknesses\n          to enable remote command execution as the Apache user. By setting\n          SkipEscalation to false, this module will attempt to setuid the bash shell.",
  "disclosure_date": "2009-02-25",
  "fullname": "exploit/unix/http/contentkeeperweb_mimencode",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:59:31 +0000",
  "name": "ContentKeeper Web Remote Command Execution",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "unknown-reliability"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "unknown-stability"
    ]
  },
  "path": "/modules/exploits/unix/http/contentkeeperweb_mimencode.rb",
  "platform": "Unix",
  "post_auth": false,
  "rank": 600,
  "ref_name": "unix/http/contentkeeperweb_mimencode",
  "references": [
    "CVE-2009-20011",
    "OSVDB-54551",
    "OSVDB-54552",
    "URL-http://www.aushack.com/200904-contentkeeper.txt"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "Automatic"
  ],
  "type": "exploit"
}
—
Severity
severity
GitHub advisoriescritical
GitHub's own rating, from the CVSS base score at 9.0 and above.
receipt
Source
GitHub advisories
Its words
critical
Read by
field:severity
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-02 12:00 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2009-20011",
  "cvss": {
    "score": null,
    "vector_string": null
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 0.0,
      "vector_string": null
    },
    "cvss_v4": {
      "score": 10.0,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-78",
      "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"
    }
  ],
  "description": "ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful.",
  "epss": {
    "percentage": 0.01358,
    "percentile": 0.70511
  },
  "ghsa_id": "GHSA-w8w9-prcc-w4vw",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-w8w9-prcc-w4vw",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-w8w9-prcc-w4vw"
    },
    {
      "type": "CVE",
      "value": "CVE-2009-20011"
    }
  ],
  "nvd_published_at": "2025-08-30T14:15:35Z",
  "published_at": "2026-10-02T00:31:21Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2009-20011",
    "https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/http/contentkeeperweb_mimencode.rb",
    "https://web.archive.org/web/20081220084819/http://www.contentkeeper.com",
    "https://www.ativion.com/contentkeeper",
    "https://www.vulncheck.com/advisories/contentkeeper-web-appliance-rce-via-mimencode",
    "http://www.aushack.com/200904-contentkeeper.txt",
    "https://github.com/advisories/GHSA-w8w9-prcc-w4vw"
  ],
  "repository_advisory_url": null,
  "severity": "critical",
  "source_code_location": "",
  "summary": "ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are...",
  "type": "unreviewed",
  "updated_at": "2026-10-02T00:31:28Z",
  "url": "https://api.github.com/advisories/GHSA-w8w9-prcc-w4vw",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Status
status
NVDDeferred
receipt
Source
NVD
Its words
Deferred
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "mimencode CGI handler",
              "/cgi-bin/ck/mimencode"
            ],
            "product": "ContentKeeper Web Appliance",
            "vendor": "ContentKeeper Technologies",
            "versions": [
              {
                "lessThan": "125.10",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful."
      },
      {
        "lang": "es",
        "value": "ContentKeeper Web Appliance (ahora mantenido por Impero Software) versiones anteriores a la 125.10 son vulnerables a la ejecución remota de comandos debido al manejo inseguro de cargas de archivos a través de la utilidad CGI mimencode. La vulnerabilidad permite a atacantes no autenticados cargar y ejecutar scripts arbitrarios como el usuario Apache. Además, el exploit puede escalar privilegios opcionalmente abusando del uso inseguro de PATH en el binario benetool, lo que resulta en acceso a nivel de root si tiene éxito."
      }
    ],
    "id": "CVE-2009-20011",
    "lastModified": "2026-10-01T23:10:00.233",
    "metrics": {
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 10.0,
            "baseSeverity": "CRITICAL",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "HIGH",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2009-20011",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-09-02T20:42:55.453012Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-30T14:15:35.140",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "http://www.aushack.com/200904-contentkeeper.txt"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/http/contentkeeperweb_mimencode.rb"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://web.archive.org/web/20081220084819/http://www.contentkeeper.com/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.ativion.com/contentkeeper/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/contentkeeper-web-appliance-rce-via-mimencode"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-78"
          },
          {
            "lang": "en",
            "value": "CWE-434"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDContentKeeper Technologies
receipt
Source
NVD
Its words
ContentKeeper Technologies
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "mimencode CGI handler",
              "/cgi-bin/ck/mimencode"
            ],
            "product": "ContentKeeper Web Appliance",
            "vendor": "ContentKeeper Technologies",
            "versions": [
              {
                "lessThan": "125.10",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful."
      },
      {
        "lang": "es",
        "value": "ContentKeeper Web Appliance (ahora mantenido por Impero Software) versiones anteriores a la 125.10 son vulnerables a la ejecución remota de comandos debido al manejo inseguro de cargas de archivos a través de la utilidad CGI mimencode. La vulnerabilidad permite a atacantes no autenticados cargar y ejecutar scripts arbitrarios como el usuario Apache. Además, el exploit puede escalar privilegios opcionalmente abusando del uso inseguro de PATH en el binario benetool, lo que resulta en acceso a nivel de root si tiene éxito."
      }
    ],
    "id": "CVE-2009-20011",
    "lastModified": "2026-10-01T23:10:00.233",
    "metrics": {
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 10.0,
            "baseSeverity": "CRITICAL",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "HIGH",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2009-20011",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-09-02T20:42:55.453012Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-30T14:15:35.140",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "http://www.aushack.com/200904-contentkeeper.txt"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/http/contentkeeperweb_mimencode.rb"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://web.archive.org/web/20081220084819/http://www.contentkeeper.com/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.ativion.com/contentkeeper/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/contentkeeper-web-appliance-rce-via-mimencode"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-78"
          },
          {
            "lang": "en",
            "value": "CWE-434"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful.
zetlyn/cve-nvd · 2025-08-30
product ContentKeeper Web Appliance status Deferred vendor ContentKeeper Technologies source
ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are...
zetlyn/cve-ghsa · 2026-10-02
cwe CWE-78 severity critical source

exploit

ContentKeeper Web Remote Command Execution
zetlyn/cve-metasploit · 2009-02-25
platform Unix rank 600 source