CVE-2009-4806
admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to read or modify the administrator's credentials via unspecified vectors.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.64%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to read or modify the administrator's credentials via unspecified vectors. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.64% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- digitalinterchange/digital interchange document library
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/34129Vendor Advisory
- http://www.exploit-db.com/exploits/8130
- http://www.securityfocus.com/bid/33983
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49018
- http://secunia.com/advisories/34129Vendor Advisory
- http://www.exploit-db.com/exploits/8130
- http://www.securityfocus.com/bid/33983
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49018
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.