peter bassill · operator
$ cve CVE-2009-1638 JSON

CVE-2009-1638 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.6% (pctl 85)

Patch early

A public exploit exists.

Description

Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access by setting the JobCareerAdmin cookie to Login.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.62% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2009-05-15
Last modified2026-06-16

Affected (1)

VendorProduct
t-dreamsjob career package

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD