CVE-2009-4465

D

eluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and configuration information, log data, and gain administrative access via a direct request to scripts in (1) templates/ including (2) templates/deluxe/admincp/, (3) templates/corporate/admincp/, and (4) templates/blue/admincp/; (5) images/; (6) logs/ including (7) logs/cp.php; (8) wysiwyg/; (9) docs/; (10) classes/; (11) lang/; and (12) settings/.

Configurations

Configuration 1 (hide)

cpe:2.3:a:deluxebb:deluxebb:1.3:*:*:*:*:*:*:*

History

21 Nov 2024, 01:09

Type Values Removed Values Added
References () http://www.exploit-db.com/exploits/10598 - Exploit () http://www.exploit-db.com/exploits/10598 - Exploit
References () http://www.securityfocus.com/bid/37448 - Exploit () http://www.securityfocus.com/bid/37448 - Exploit
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/54975 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/54975 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/54977 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/54977 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/54978 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/54978 -

Information

Published : 2009-12-30 20:00

Updated : 2025-04-09 00:30


NVD link : CVE-2009-4465

Mitre link : CVE-2009-4465

CVE.ORG link : CVE-2009-4465


JSON object : View

Products Affected
CWE
CWE-264

Permissions, Privileges, and Access Controls