CVE-2009-2025 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.6% (pctl 85)
Patch early
A public exploit exists.
Description
admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) GROUPID, (3) GROUP, and (4) USERID cookies to certain values.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.61% — more likely to be exploited than 85% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-06-09 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| dutchmonkey | dm filemanager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | DM FileManager 3.9.2 - Insecure Cookie Handling | 2009-06-08 |
References
→ the Explorer · watch your stack · NVD