peter bassill · operator
$ cve CVE-2009-1813 JSON

CVE-2009-1813 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.3% (pctl 83)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in admin/index.php in Submitter Script 2 allow remote attackers to execute arbitrary SQL commands via (1) the uNev parameter (aka the username field) or (2) the uJelszo parameter (aka the Password field).

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.31% — more likely to be exploited than 83% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2009-05-29
Last modified2026-06-16

Affected (1)

VendorProduct
submitterscriptsubmitterscript

Public exploits

SourceTitleDate
exploit-dbSubmitter Script - Authentication Bypass2009-05-14

References

→ the Explorer  ·  watch your stack  ·  NVD