CVE-2009-0753

mldonkey 2.8.4-2.9.7 - Path Traversal via Leading Double Slash

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-0753. PoCs published by Michael Peselnik.

AI-analyzed exploit summary The exploit leverages a directory traversal vulnerability in MLdonkey's HTTP GUI (tcp/4080) by using a double slash (//) to bypass path sanitization, allowing unauthorized access to arbitrary files on the system. The PoC demonstrates this by fetching /etc/passwd via a crafted HTTP request.

Description

Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files via a leading "//" (double slash) in the filename.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Michael Peselnik · textremotemultiple
https://www.exploit-db.com/exploits/8097

The exploit leverages a directory traversal vulnerability in MLdonkey's HTTP GUI (tcp/4080) by using a double slash (//) to bypass path sanitization, allowing unauthorized access to arbitrary files on the system. The PoC demonstrates this by fetching /etc/passwd via a crafted HTTP request.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: MLdonkey up to 2.9.7
No auth needed
Prerequisites: Network access to the MLdonkey HTTP GUI (typically tcp/4080) · MLdonkey daemon running with insufficient path sanitization
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (12)

Core 12
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33865
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8097
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34008
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34436
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/02/23/1
Various Sources x_refsource_confirm
http://savannah.nongnu.org/bugs/?25667
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200903-36.xml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34345
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1739
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34306

Scores

EPSS 0.1088
EPSS Percentile 93.5%

Details

CWE
CWE-22
Status published
Products (5)
mldonkey/mldonkey 2.8.4
mldonkey/mldonkey 2.8.7
mldonkey/mldonkey 2.9
mldonkey/mldonkey 2.9.0-r3
mldonkey/mldonkey 2.9.7
Published Mar 03, 2009
Tracked Since Feb 18, 2026