7.5
CVSSv2

CVE-2009-4465

Published: 30/12/2009 Updated: 17/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote malicious users to obtain user and configuration information, log data, and gain administrative access via a direct request to scripts in (1) templates/ including (2) templates/deluxe/admincp/, (3) templates/corporate/admincp/, and (4) templates/blue/admincp/; (5) images/; (6) logs/ including (7) logs/cp.php; (8) wysiwyg/; (9) docs/; (10) classes/; (11) lang/; and (12) settings/.

Vulnerable Product Search on Vulmon Subscribe to Product

deluxebb deluxebb 1.3

Exploits

# Author: cp77fk4r | Empty0pagE[Shift+2]gmailcom<gmailcom> # Vendor: wwwdeluxebbcom # #[Directory Listing] server/templates/ server/images/ server/logs/ server/wysiwyg/ server/docs/ server/classes server/lang server/settings/ # # #[Cross Site Scripting] server/mi ...