Back

HIGH

ContentKeeper Web Appliance < 125.10 Arbitrary File Access via mimencode

Published Aug 20, 2025

Description

ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 expose the mimencode binary via a CGI endpoint, allowing unauthenticated attackers to retrieve arbitrary files from the filesystem. By crafting a POST request to /cgi-bin/ck/mimencode with traversal and output parameters, attackers can read sensitive files such as /etc/passwd outside the webroot.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 20, 2025
Updated Jul 15, 2026
Reserved Aug 18, 2025
CISA Vulnrichment
Updated Aug 20, 2025
NVD
Status Deferred
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Aug 20, 2025
Updated Jul 15, 2026
Exploited since n/a
EUVD-2009-5116