Vulnerability Report

CVE-2009-4137

RCE

Title: Matomo RCE

RCE

Proof Of Concept

PoC Available for CVE-2009-4137

CWE Category CWE-20
Published Date Dec 24, 2009
Modified Date Apr 09, 2025
Exploit Status Available
Score 7.5 CVSS v2.0
Exploit Probability (EPSS)
4.88%

Vulnerability Summary

CVE-2009-4137: The loadContentFromCookie function in core/Cookie.php in Piwik before 0.5 does not validate strings obtained from cookies before calling the unserialize function, which allows remote attackers to execute arbitrary code or upload arbitrary files via vectors related to the __destruct function in the Piwik_Config class; php://filter URIs; the __destruct functions in Zend Framework, as demonstrated by the Zend_Log destructor; the shutdown functions in Zend Framework, as demonstrated by the Zend_Log_Writer_Mail class; the render function in the Piwik_View class; Smarty templates; and the _eval function in Smarty.

CVSS v2.0
Source Entity [email protected]
Severity HIGH
7.5
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:L/Au:N/C:P/I:P/A:P

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2009-4137 Exploits & PoCs (Proof Of Concept)

GitHub https://github.com/Alexeyan/CVE-2009-4137
View Code
MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected Stack

No specific products linked.