CVE-2009-4088
Estado: ModificadaMedia (6.8)—
Multiple directory traversal vulnerabilities in telepark.wiki 2.4.23 and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the css parameter to (1) getjs.php and (2) getcsslocal.php; and include and execute arbitrary local files via the (3) group parameter to upload.php.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.80%
- Percentil entre todas las CVEs puntuadas: 86
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-22
Referencias
- http://blog.telepark.com/telepark-web-software/2009/11/09/telepark-wiki-security-fixes/
- http://packetstormsecurity.org/0911-exploits/Telepark-fixes-nov09-2.txt
- http://secunia.com/advisories/37391
- http://www.exploit-db.com/exploits/9483
- http://www.osvdb.org/60216
- http://www.osvdb.org/60217
- http://www.osvdb.org/60218
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54327
- http://blog.telepark.com/telepark-web-software/2009/11/09/telepark-wiki-security-fixes/
- http://packetstormsecurity.org/0911-exploits/Telepark-fixes-nov09-2.txt
- http://secunia.com/advisories/37391
- http://www.exploit-db.com/exploits/9483
- http://www.osvdb.org/60216
- http://www.osvdb.org/60217
- http://www.osvdb.org/60218
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54327
JSON original (NVD)
Mostrar
{
"id": "CVE-2009-4088",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-11-29T13:07:34.843",
"references": [
{
"url": "http://blog.telepark.com/telepark-web-software/2009/11/09/telepark-wiki-security-fixes/",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.org/0911-exploits/Telepark-fixes-nov09-2.txt",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/37391",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.exploit-db.com/exploits/9483",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/60216",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/60217",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/60218",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/54327",
"source": "cve@mitre.org"
},
{
"url": "http://blog.telepark.com/telepark-web-software/2009/11/09/telepark-wiki-security-fixes/",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://packetstormsecurity.org/0911-exploits/Telepark-fixes-nov09-2.txt",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/37391",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.exploit-db.com/exploits/9483",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/60216",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/60217",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/60218",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/54327",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple directory traversal vulnerabilities in telepark.wiki 2.4.23 and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the css parameter to (1) getjs.php and (2) getcsslocal.php; and include and execute arbitrary local files via the (3) group parameter to upload.php."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de salto de directorio en telepark.wiki v2.4.23 y anteriores, permite a atacantes remotos leer ficheros de su elección a través de secuencias de directorios cruzados en el parámetro css sobre (1) getjs.php y (2) getcsslocal.php; e incluir y ejecutar ficheros locales de su elección a través del parámetro (3) group sobre upload.php"
}
],
"lastModified": "2026-06-16T23:13:00.850",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:telepark:telepark.wiki:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F0052665-E37F-4F11-BBE0-43B2A99A8C20",
"versionEndIncluding": "2.4.23"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}