CVE-2009-1941 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 2.3% (pctl 83)
Patch early
A public exploit exists.
Description
PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for dbbackup.txt.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 2.29% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-06-05 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| phpeasycode | pad site scripts |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PAD Site Scripts 3.6 - Arbitrary Database Backup | 2009-06-01 |
References
→ the Explorer · watch your stack · NVD