CVE-2009-10005EPSS p54.4%
CVE-2009-10005CVE-2009-10005
Description
ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 expose the mimencode binary via a CGI endpoint, allowing unauthenticated attackers to retrieve arbitrary files from the filesystem. By crafting a POST request to /cgi-bin/ck/mimencode with traversal and output parameters, attackers can read sensitive files such as /etc/passwd outside the webroot.
Scoring
| EPSS | 0.78% probability of exploitation · percentile 54.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-01 |