Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2009-10005 1 Contentkeeper Technologies 1 Contentkeeper 2025-08-24 N/A
ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 expose the mimencode binary via a CGI endpoint, allowing unauthenticated attackers to retrieve arbitrary files from the filesystem. By crafting a POST request to /cgi-bin/ck/mimencode with traversal and output parameters, attackers can read sensitive files such as /etc/passwd outside the webroot.
CVE-2006-5018 1 Contentkeeper Technologies 1 Contentkeeper 2025-04-09 N/A
ContentKeeper 123.25 and earlier places passwords in cleartext in an INPUT element in cgi-bin/ck/changepw.cgi, which allows remote authenticated users to obtain passwords via this URI.