Back to Database
Status published
Medium
CVE-2009-2944
Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before...
Vulnerability Description
Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read arbitrary files via crafted TeX commands.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-2944
Credits & Attribution
No credits recorded in the NVD database.
References
- http://osvdb.org/57575
- http://ikiwiki.info/security/#index35h2
- http://secunia.com/advisories/36516
- http://secunia.com/advisories/36539
- http://www.debian.org/security/2009/dsa-1875
- http://www.securityfocus.com/bid/36181
- http://www.vupen.com/english/advisories/2009/2475
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52922
More from ikiwiki
View All →CVE-2019-9187
ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows...
High
7.5
CVE-2017-0356
Authentication bypass via repeated parameters
Critical
9.8
CVE-2016-9646
Commit metadata forgery via CGI::FormBuilder context-dependent APIs
Medium
5.3
CVE-2016-9645
Editing restriction bypass for git revert
Medium
6.5
CVE-2016-4561
Cross-site scripting (XSS) vulnerability in the cgierror function in CGI.pm...
Medium
6.1
Affected Vendor
ikiwiki
View all reports →Affected Software
ikiwiki
Vulnerable Versions:
0, 2.0, 2.00, 2.1, 2.2, 2.3, 2.4, 2.5, 2.6, 2.6.1, 2.7, 2.8, 2.9, 2.10, 2.11, 2.12, 2.13, 2.14, 2.15, 2.16, 2.17, 2.18, 2.19, 2.20, 2.30, 2.31, 2.31.1, 2.31.2, 2.31.3, 2.40, 2.41, 2.42, 2.43, 2.44, 2.45, 2.46, 2.47, 2.48, 2.49, 2.50, 2.51, 2.52, 2.53, 2.54, 2.55, 2.56, 2.60, 2.61, 2.62, 2.62.1, 2.63, 2.64, 2.65, 2.66, 2.67, 2.68, 2.69, 2.70, 2.71, 2.72, 3.0, 3.00, 3.01, 3.02, 3.03, 3.04, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12, 3.13, 3.14, 3.141, 3.1415, 3.14159
Timeline
Official Publish:
August 31st, 2009
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.