CVE-2009-20011 - CVE House
Back to Database
Status published Critical CVE-2009-20011

ContentKeeper Web Appliance < 125.10 RCE via mimencode

Vulnerability Description

ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-20011

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Patrick Webster (aushack)

Affected Vendor

ContentKeeper Technologies

View all reports →

Affected Software

ContentKeeper Web Appliance
Vulnerable Versions:
0

Timeline

Official Publish: August 30th, 2025
Last Modified: May 15th, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)