← back
CVE-2009-2138

CVE-2009-2138

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 1.3%
exploitation probability
1.3%top 33% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Multiple open redirect vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the returnto parameter to login.php or (2) the returnto parameter in a delete action to news.php. NOTE: this can be leveraged for cross-site scripting (XSS) by redirecting to a data: URI.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.