CVE-2009-0331 describes a directory traversal vulnerability in Enhanced Simple PHP Gallery (ESPG) version 1.72, specifically within the gallery/comment.php script, which may also affect the "my little homepage Comment script." This flaw allows unauthenticated remote attackers to read arbitrary files on the server by manipulating the 'file' parameter with directory traversal sequences. The vulnerability carries a CVSS score of 7.8 (High), indicating a critical severity. It is easily exploitable over the network with low attack complexity and no authentication required, potentially leading to complete confidentiality compromise (C:C) as attackers can access sensitive system files. While there is no evidence of active exploitation in the wild (KEV: No) and no Metasploit or Nuclei modules exist, exploit code is publicly available on ExploitDB (EDB-7819). Despite this, the vulnerability has garnered minimal community discussion and media coverage, suggesting it is not widely recognized or actively targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.72CPE matchmatch criteria | cpe:2.3:a:quirm:espg:1.72:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.