CVE-2009-2003 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.5% (pctl 84)
Patch early
A public exploit exists.
Description
Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative access by setting the (1) c7portal and (2) cookname cookies to "admin."
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.51% — more likely to be exploited than 84% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-06-08 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ascadnetworks | password protector sd |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Ascad Networks 5 - Products Insecure Cookie Handling | 2009-05-14 |
| exploit-db | Password Protector SD 1.3.1 - Insecure Cookie Handling | 2009-05-13 |
References
→ the Explorer · watch your stack · NVD