CVE-2010-2786: Path Traversal
Published Aug 2, 2010
·Updated
Directory traversal vulnerability in Piwik 0.6 through 0.6.3 allows remote attackers to include arbitrary local files and possibly have unspecified other impact via directory traversal sequences in a crafted data-renderer request.
Affected Software
6 affected components
Matomo Matomo=0.6
Matomo Matomo=0.6.1
Matomo Matomo=0.6.2
Matomo Matomo=0.6.3-rc1
Matomo Matomo=0.6.3
Matomo Matomo=0.6.3-rc2
Event History
Aug 2, 2010
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-2786?
CVE-2010-2786 is considered to have a medium severity due to its potential for arbitrary file inclusion.
2
How do I fix CVE-2010-2786?
To fix CVE-2010-2786, upgrade Piwik to version 0.6.4 or later, which addresses this vulnerability.
3
What types of attacks are possible through CVE-2010-2786?
CVE-2010-2786 allows attackers to conduct remote file inclusion attacks, potentially leading to code execution on the server.
4
Which versions of Piwik are affected by CVE-2010-2786?
CVE-2010-2786 affects Piwik versions 0.6 through 0.6.3.
5
Is CVE-2010-2786 still a risk if using a newer version of Piwik?
If you are using a version of Piwik later than 0.6.4, CVE-2010-2786 is no longer a risk.