CVE-2009-2080 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.7% (pctl 85)
Patch early
A public exploit exists.
Description
admin.php in MRCGIGUY The Ticket System 2.0 does not properly restrict access, which allows remote attackers to (1) obtain sensitive configuration information via the editconfig action or (2) change the administrator's password via the id parameter in an editop action.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.69% — more likely to be exploited than 85% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-06-16 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| mrcgiguy | the ticket system |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | mrcgiguy the ticket system 2.0 PHP - Multiple Vulnerabilities | 2009-06-09 |
References
→ the Explorer · watch your stack · NVD