CVE-2009-20011

ContentKeeper Web Appliance <125.10 - RCE

Title source: llm

Description

ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful.

Exploits (1)

metasploit WORKING POC EXCELLENT
by aushack · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/http/contentkeeperweb_mimencode.rb

Scores

EPSS 0.6044
EPSS Percentile 98.2%

Classification

CWE
CWE-78 CWE-434
Status draft

Timeline

Published Aug 30, 2025
Tracked Since Feb 18, 2026