← Vulnerability feed

Vulnerability record · CVE-2009-4140 · published 22 December 2009

CVE-2009-4140: Open Flash Chart unrestricted file upload enables remote code execution

TTeethgrinder.Co.Uk · Open Flash Chart

ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as bundled in Piwik 0.2.35 through 0.4.3 and the Woopra Analytics Plugin before 1.4.3.2, accepts an uploaded file whose name and content are attacker-controlled. When register_globals is enabled, a remote authenticated user can write a file with an executable extension into tmp-upload-images/ and then request it directly, achieving code execution.

7.5 CVSS 2.0 High EPSS 76% · top 0.5%
7.5CVSS 2.0 base score
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
32References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0.2.35 through 0.4.3, Woopra Analytics Plugin before 1.4.3.2, and possibly other products, when register_globals is enabled, allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension through the name parameter with the code in the HTTP_RAW_POST_DATA parameter, then accessing it via a direct request to the file in tmp-upload-images/.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote code execution with public exploit code and very high EPSS, though it requires authentication and register_globals enabled.

What it is

ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as bundled in Piwik 0.2.35 through 0.4.3 and the Woopra Analytics Plugin before 1.4.3.2, accepts an uploaded file whose name and content are attacker-controlled. When register_globals is enabled, a remote authenticated user can write a file with an executable extension into tmp-upload-images/ and then request it directly, achieving code execution.

Impact

An attacker with a valid account gains arbitrary code execution under the web server's user, allowing full compromise of the host and any data it can reach.

Attack surface

Reached over the network through the ofc_upload_image.php endpoint; the description requires an authenticated user, and no user interaction beyond the upload request is described. Exploitation depends on the PHP register_globals setting being enabled.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.758, 99.5th percentile) and multiple references are tagged Exploit, including public exploit-db and Packet Storm entries.

What to do

  • Upgrade or remove the affected Open Flash Chart component; apply the Piwik and Woopra Analytics Plugin fixes referenced in the vendor advisories.
  • Disable PHP register_globals, which the description identifies as a precondition for exploitation.
  • Restrict or block direct HTTP access to the tmp-upload-images/ directory and disallow script execution there.
  • Enforce upload validation: whitelist extensions, verify content type, and store uploads outside the web root.
  • Limit accounts that can reach the upload endpoint and review them for least privilege.

Detection

  • Monitor web logs for POST requests to ofc_upload_image.php followed by GET requests to files under tmp-upload-images/.
  • Alert on newly created executable files (for example .php) inside upload or tmp directories.
  • Check PHP configuration for register_globals being enabled on hosts running the affected products.
  • Hunt for unexpected outbound connections or child processes spawned by the web server user.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/123493/wpseowatcher-exec.txt
http://packetstormsecurity.com/files/123494/wpslimstatex-exec.txt
http://packetstormsecurity.org/0910-exploits/piwik-upload.txt Exploit
http://piwik.org/blog/2009/10/piwik-response-to-secunia-advisory-sa37078/ Vendor Advisory
http://secunia.com/advisories/37078 Vendor Advisory
http://secunia.com/advisories/37911 Vendor Advisory
http://secunia.com/advisories/55160
http://secunia.com/advisories/55162
http://wordpress.org/extend/plugins/woopra/changelog/
http://www.exploit-db.com/exploits/24969
http://www.openwall.com/lists/oss-security/2009/12/14/1
http://www.openwall.com/lists/oss-security/2009/12/14/3
http://www.osvdb.org/59051
http://www.securityfocus.com/bid/37314 Exploit
http://www.vupen.com/english/advisories/2009/2966 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/53825
http://packetstormsecurity.com/files/123493/wpseowatcher-exec.txt
http://packetstormsecurity.com/files/123494/wpslimstatex-exec.txt
http://packetstormsecurity.org/0910-exploits/piwik-upload.txt Exploit
http://piwik.org/blog/2009/10/piwik-response-to-secunia-advisory-sa37078/ Vendor Advisory
http://secunia.com/advisories/37078 Vendor Advisory
http://secunia.com/advisories/37911 Vendor Advisory
http://secunia.com/advisories/55160
http://secunia.com/advisories/55162
http://wordpress.org/extend/plugins/woopra/changelog/
http://www.exploit-db.com/exploits/24969
http://www.openwall.com/lists/oss-security/2009/12/14/1
http://www.openwall.com/lists/oss-security/2009/12/14/3
http://www.osvdb.org/59051
http://www.securityfocus.com/bid/37314 Exploit
http://www.vupen.com/english/advisories/2009/2966 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/53825

Track CVE-2009-4140 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2015-7816Matomo vulnerabilityThe DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP object injection at…EPSS 3.9%7.5CVE-2015-7815Matomo path traversal vulnerabilityDirectory traversal vulnerability in core/ViewDataTable/Factory.php in Piwik before 2.15.0 allows remote attackers to include and execute arbitrary l…EPSS 3.0%7.5CVE-2009-4137Matomo improper input validation vulnerabilityThe loadContentFromCookie function in core/Cookie.php in Piwik before 0.5 does not validate strings obtained from cookies before calling the unserial…EPSS 17%6.8CVE-2011-4941Matomo vulnerabilityUnspecified vulnerability in Piwik 1.2 through 1.4 allows remote attackers with the view permission to execute arbitrary code via unknown attack vect…EPSS 2.3%6.8CVE-2010-2786Matomo path traversal vulnerabilityDirectory traversal vulnerability in Piwik 0.6 through 0.6.3 allows remote attackers to include arbitrary local files and possibly have unspecified o…EPSS 2.7%6.4CVE-2011-0398Matomo permissions and access controls vulnerabilityThe Piwik_Common::getIP function in Piwik before 1.1 does not properly determine the client IP address, which allows remote attackers to bypass inten…EPSS 1.3%6.1CVE-2023-6923Matomo cross-site scripting vulnerabilityThe Matomo Analytics – Ethical Stats. Powerful Insights. plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the idsite paramete…EPSS 0.55%6.1CVE-2013-0193Matomo cross-site scripting vulnerabilityCross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This …EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2009-4140), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.