CVE-2009-1771 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.5% (pctl 84)
Patch early
A public exploit exists.
Description
index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which allows remote attackers to create or modify admin accounts via the (1) users[fullname], (2) users[email], (3) users[role_id], (4) users[username], and (5) users[password] parameters.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.46% — more likely to be exploited than 84% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-05-22 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| flyspeck | flyspeck cms |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Flyspeck CMS 6.8 - Local/Remote File Inclusion / Change Add Admin | 2009-05-18 |
References
→ the Explorer · watch your stack · NVD