← back
CVE-2009-4465

CVE-2009-4465

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 2.4%
from disclosure to weapon0 days
Published on NVDDec 30
1st PoCDec 22
exploitation probability
2.4%top 18% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and configuration information, log data, and gain administrative access via a direct request to scripts in (1) templates/ including (2) templates/deluxe/admincp/, (3) templates/corporate/admincp/, and (4) templates/blue/admincp/; (5) images/; (6) logs/ including (7) logs/cp.php; (8) wysiwyg/; (9) docs/; (10) classes/; (11) lang/; and (12) settings/.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.