peter bassill · operator
$ cve CVE-2009-4465 JSON

CVE-2009-4465 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 83)

Patch early

A public exploit exists.

Description

DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and configuration information, log data, and gain administrative access via a direct request to scripts in (1) templates/ including (2) templates/deluxe/admincp/, (3) templates/corporate/admincp/, and (4) templates/blue/admincp/; (5) images/; (6) logs/ including (7) logs/cp.php; (8) wysiwyg/; (9) docs/; (10) classes/; (11) lang/; and (12) settings/.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.37% — more likely to be exploited than 83% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2009-12-30
Last modified2026-06-16

Affected (1)

VendorProduct
deluxebbdeluxebb

Public exploits

SourceTitleDate
exploit-dbDeluxeBB 1.3 - Multiple Vulnerabilities2009-12-22

References

→ the Explorer  ·  watch your stack  ·  NVD