peter bassill · operator
$ cve CVE-2009-1247 JSON

CVE-2009-1247 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 13.7% (pctl 96)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in login.php in Acute Control Panel 1.0.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS13.7% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2009-04-06
Last modified2026-06-16

Affected (1)

VendorProduct
acutecp.rediscussedacutecp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD