CVE-2009-2382

admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access by setting the PHPMYBCAdmin cookie to LOGGEDIN.
References
Link Resource
http://osvdb.org/55505 Broken Link Exploit
http://secunia.com/advisories/35660 Broken Link Vendor Advisory
http://www.exploit-db.com/exploits/9053 Exploit Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/51445 Third Party Advisory VDB Entry
http://osvdb.org/55505 Broken Link Exploit
http://secunia.com/advisories/35660 Broken Link Vendor Advisory
http://www.exploit-db.com/exploits/9053 Exploit Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/51445 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:jay-jayx0r:phpmyblockchecker:1.0.0055:*:*:*:*:*:*:*

History

21 Nov 2024, 01:04

Type Values Removed Values Added
References () http://osvdb.org/55505 - Broken Link, Exploit () http://osvdb.org/55505 - Broken Link, Exploit
References () http://secunia.com/advisories/35660 - Broken Link, Vendor Advisory () http://secunia.com/advisories/35660 - Broken Link, Vendor Advisory
References () http://www.exploit-db.com/exploits/9053 - Exploit, Third Party Advisory, VDB Entry () http://www.exploit-db.com/exploits/9053 - Exploit, Third Party Advisory, VDB Entry
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/51445 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/51445 - Third Party Advisory, VDB Entry

13 Feb 2024, 17:44

Type Values Removed Values Added
CVSS v2 : 7.5
v3 : unknown
v2 : 7.5
v3 : 9.8
References (OSVDB) http://osvdb.org/55505 - Exploit (OSVDB) http://osvdb.org/55505 - Broken Link, Exploit
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/51445 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/51445 - Third Party Advisory, VDB Entry
References (SECUNIA) http://secunia.com/advisories/35660 - Vendor Advisory (SECUNIA) http://secunia.com/advisories/35660 - Broken Link, Vendor Advisory
References (EXPLOIT-DB) http://www.exploit-db.com/exploits/9053 - (EXPLOIT-DB) http://www.exploit-db.com/exploits/9053 - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2009-07-08 15:30

Updated : 2024-11-21 01:04


NVD link : CVE-2009-2382

Mitre link : CVE-2009-2382

CVE.ORG link : CVE-2009-2382


JSON object : View

Products Affected

jay-jayx0r

  • phpmyblockchecker
CWE
CWE-287

Improper Authentication