7.5
CVE-2009-2025
- EPSS 2.61%
- Veröffentlicht 09.06.2009 19:30:00
- Zuletzt bearbeitet 16.06.2026 23:08:35
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) GROUPID, (3) GROUP, and (4) USERID cookies to certain values.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dutchmonkey ≫ Dm Filemanager Version3.9.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.61% | 0.834 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/35167
http://www.vupen.com/english/advisories/2009/1532
https://www.exploit-db.com/exploits/8903