CVE-2009-2025

admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) GROUPID, (3) GROUP, and (4) USERID cookies to certain values.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dutchmonkey:dm_filemanager:3.9.2:*:*:*:*:*:*:*

History

21 Nov 2024, 01:03

Type Values Removed Values Added
References () http://secunia.com/advisories/35167 - Vendor Advisory () http://secunia.com/advisories/35167 - Vendor Advisory
References () http://www.vupen.com/english/advisories/2009/1532 - Vendor Advisory () http://www.vupen.com/english/advisories/2009/1532 - Vendor Advisory
References () https://www.exploit-db.com/exploits/8903 - () https://www.exploit-db.com/exploits/8903 -

Information

Published : 2009-06-09 19:30

Updated : 2024-11-21 01:03


NVD link : CVE-2009-2025

Mitre link : CVE-2009-2025

CVE.ORG link : CVE-2009-2025


JSON object : View

Products Affected

dutchmonkey

  • dm_filemanager
CWE
CWE-264

Permissions, Privileges, and Access Controls