CVE-2009-4665

CuteSoft Components Cute Editor - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-4665. PoCs published by Securitylab.ir.

AI-analyzed exploit summary This is a writeup describing a directory traversal vulnerability in Cute Editor ASP.NET, allowing remote file download via a crafted URL. No exploit code is provided, only a proof-of-concept URL and affected sites.

Description

Directory traversal vulnerability in CuteSoft_Client/CuteEditor/Load.ashx in CuteSoft Components Cute Editor for ASP.NET allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Securitylab.ir · textwebappsasp
https://www.exploit-db.com/exploits/8785

This is a writeup describing a directory traversal vulnerability in Cute Editor ASP.NET, allowing remote file download via a crafted URL. No exploit code is provided, only a proof-of-concept URL and affected sites.

Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Cute Editor ASP.NET
No auth needed
Prerequisites: access to the target web server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/8785
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35085
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/50727

Scores

EPSS 0.0298
EPSS Percentile 86.9%

Details

CWE
CWE-22
Status published
Products (2)
cutesoft_components/cute_editor_for_asp.net
nuget/CuteEditor 0 - 6.6NuGet
Published Mar 05, 2010
Tracked Since Feb 18, 2026