Vulnerability Database

289,571

Total vulnerabilities in the database

CVE-2009-0037

The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or overwrite arbitrary files via a redirect to a file: URL, or (3) execute arbitrary commands via a redirect to an scp: URL.

  • Published: Mar 5, 2009
  • Updated: Apr 13, 2023
  • CVE: CVE-2009-0037
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
curl / curl 7.10.7 7.10.7.x
curl / curl 7.10.3 7.10.3.x
curl / curl 7.3 7.3.x
curl / curl 7.1 7.1.x
curl / curl 6.4 6.4.x
curl / curl 5.11 5.11.x
curl / curl 7.14.1 7.14.1.x
curl / curl 7.9.1 7.9.1.x
curl / libcurl 7.14 7.14.x
curl / curl 6.1beta 6.1beta.x
curl / curl 7.16.3 7.16.3.x
curl / libcurl 7.14.1 7.14.1.x
curl / curl 7.9.2 7.9.2.x
curl / curl 7.14 7.14.x
curl / curl 7.4 7.4.x
curl / curl 7.9.3 7.9.3.x
curl / curl 6.3 6.3.x
curl / libcurl 7.12.2 7.12.2.x
curl / curl 6.5.1 6.5.1.x
curl / curl 7.4.1 7.4.1.x
curl / curl 7.10.4 7.10.4.x
curl / curl 7.15.3 7.15.3.x
curl / curl 7.5.2 7.5.2.x
curl / libcurl 7.13.1 7.13.1.x
curl / libcurl 7.12.1 7.12.1.x
curl / curl 7.2.1 7.2.1.x
curl / curl 6.0 6.0.x
curl / curl 7.7.3 7.7.3.x
curl / curl 7.10.5 7.10.5.x
curl / libcurl 5.11 5.11.x
curl / curl 7.9.8 7.9.8.x
curl / curl 7.7 7.7.x
curl / curl 7.10.1 7.10.1.x
curl / curl 7.16.4 7.16.4.x
curl / libcurl 7.13 7.13.x
curl / curl 7.2 7.2.x
curl / curl 7.10.6 7.10.6.x
curl / curl 7.8 7.8.x
curl / curl 7.13 7.13.x
curl / libcurl 7.15.2 7.15.2.x
curl / curl 6.3.1 6.3.1.x
curl / curl 7.12.1 7.12.1.x
curl / libcurl 7.15.3 7.15.3.x
curl / libcurl 7.12.3 7.12.3.x
curl / curl 7.9.6 7.9.6.x
curl / curl 7.8.1 7.8.1.x
curl / curl 7.15.1 7.15.1.x
curl / curl 7.7.2 7.7.2.x
curl / curl 7.9.5 7.9.5.x
curl / curl 7.10.2 7.10.2.x
curl / libcurl 7.19.3 7.19.3.x
curl / curl 7.9 7.9.x
curl / curl 7.17 7.17.x
curl / curl 7.9.7 7.9.7.x
curl / curl 7.10 7.10.x
curl / libcurl 7.15.1 7.15.1.x
curl / curl 7.19.3 7.19.3.x
curl / libcurl 7.12 7.12.x
curl / curl 7.6.1 7.6.1.x
curl / curl 7.9.4 7.9.4.x
curl / curl 6.2 6.2.x
curl / curl 7.13.2 7.13.2.x
curl / curl 7.8.2 7.8.2.x
curl / curl 7.5 7.5.x
curl / curl 7.15 7.15.x
curl / curl 7.6 7.6.x
curl / libcurl 7.16.3 7.16.3.x
curl / curl 7.7.1 7.7.1.x
curl / libcurl 7.13.2 7.13.2.x
curl / curl 7.10.8 7.10.8.x
curl / libcurl 7.15 7.15.x
curl / curl 7.18 7.18.x
curl / curl 6.5 6.5.x
curl / curl 6.5.2 6.5.2.x
curl / curl 7.1.1 7.1.1.x
curl / curl 7.12.2 7.12.2.x
curl / curl 7.12 7.12.x
curl / curl 7.11.1 7.11.1.x
curl / curl 7.4.2 7.4.2.x
curl / curl 7.5.1 7.5.1.x