Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

ContentKeeper Web Appliance Arbitrary File Access Vulnerability via CGI Endpoint

Vulnerability

A vulnerability exists in ContentKeeper Web Appliance versions prior to 125.10, allowing unauthenticated attackers to access arbitrary files on the filesystem. This is achieved by exploiting the 'mimencode' binary, which is exposed through a CGI endpoint. Attackers can craft a POST request to the '/cgi-bin/ck/mimencode' endpoint, using traversal and output parameters to read sensitive files, such as '/etc/passwd', outside the webroot.

Impact

Exploitation of this vulnerability allows for unauthorized access to sensitive files on the affected system. Additionally, according to the aushack.com advisory, this vulnerability could be combined with a remote command execution and privilege escalation vulnerability also present in versions through 125.09, leading to a full root compromise.

Reproduction

To reproduce this vulnerability, send a POST request to the '/cgi-bin/ck/mimencode' CGI endpoint. Include traversal and output parameters to access files outside the webroot, such as '/etc/passwd'. The response will contain the requested file, encoded in base64. This vulnerability can be exploited using a Metasploit module available in the Metasploit Framework.

Remediation

Users are advised to upgrade to ContentKeeper Web Appliance version 125.10 or above.

Added: Aug 20, 2025, 4:42 PM
Updated: Aug 20, 2025, 4:42 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
9.1
remediation
7.7
relevance
0.4
threat
9.1
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.