peter bassill · operator
$ cve CVE-2009-2605 JSON

CVE-2009-2605 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 2% (pctl 80)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in adminquery.php in Traidnt Up 2.0 allow remote attackers to execute arbitrary SQL commands via (1) trupuser and (2) truppassword cookies to uploadcp/index.php.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS1.98% — more likely to be exploited than 80% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2009-07-27
Last modified2026-06-16

Affected (1)

VendorProduct
traidnttraidnt up

Public exploits

SourceTitleDate
exploit-dbTraidnt Up 2.0 - Cookie Authentication Bypass2009-05-29

References

→ the Explorer  ·  watch your stack  ·  NVD