← Back

CVE-2009-1085

nvd nist
Published: Mar 25, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Piwik 0.2.32 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the API key and other sensitive information via a direct request for misc/cron/archive.sh.

Affected (8)

Products: Matomo: Matomo
1 product
Matomo
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Matomo
Up to 0.2.32
Version 0.2.25
Version 0.2.26
Version 0.2.27
Version 0.2.28
Version 0.2.29
Version 0.2.30
Version 0.2.31

Related CWEs

References (6)

Timeline

No history available yet.