CVE-2009-1085: Medium severity Matomo Matomo vulnerability
Published Mar 25, 2009
·Updated
Piwik 0.2.32 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the API key and other sensitive information via a direct request for misc/cron/archive.sh.
Affected Software
8 affected components
Matomo Matomo<=0.2.32
Matomo Matomo=0.2.25
Matomo Matomo=0.2.26
Matomo Matomo=0.2.27
Matomo Matomo=0.2.28
Matomo Matomo=0.2.29
Matomo Matomo=0.2.30
Matomo Matomo=0.2.31
Event History
Mar 25, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-1085?
CVE-2009-1085 is classified as a high severity vulnerability due to the unauthorized access to sensitive information.
2
How do I fix CVE-2009-1085?
To fix CVE-2009-1085, update Piwik to version 0.2.33 or later where the vulnerability has been addressed.
3
What type of vulnerability is CVE-2009-1085?
CVE-2009-1085 is a directory traversal vulnerability that allows unauthorized access to sensitive files.
4
Which versions of Piwik are affected by CVE-2009-1085?
Piwik versions 0.2.32 and earlier are affected by CVE-2009-1085.
5
What sensitive information can be accessed via CVE-2009-1085?
CVE-2009-1085 allows attackers to access the API key and other sensitive data stored in the affected Piwik installation.