{"id":"CVE-2009-4665","aliases":[],"url":"https://o3.security/vulnerability/CVE-2009-4665","summary":"CuteSoft CuteEditor Path Traversal vulnerability","details":"Directory traversal vulnerability in `CuteSoft_Client/CuteEditor/Load.ashx` in CuteSoft Components Cute Editor for ASP.NET allows remote attackers to read arbitrary files via a `..` (dot dot) in the file parameter.","published":"2022-05-02T03:56:59Z","modified":"2024-02-08T22:28:13.550299Z","cvss":null,"epss":{"score":0.06532,"percentile":0.93256,"asOf":"2026-08-21"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"NuGet","name":"CuteEditor","fixedVersion":"6.6"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2009-4665"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/50727"},{"type":"WEB","url":"https://web.archive.org/web/20200228205122/http://www.securityfocus.com/bid/35085"},{"type":"WEB","url":"http://www.exploit-db.com/exploits/8785"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-02-08T22:28:13.550299Z"}}