peter bassill · operator
$ cve CVE-2009-4657 JSON

CVE-2009-4657 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.2% (pctl 82)

Patch early

A public exploit exists.

Description

The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting to the application on port 32123, as demonstrated by setting the action option to wizardStep1.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.15% — more likely to be exploited than 82% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2010-03-03
Last modified2026-06-16

Affected (1)

VendorProduct
omidrouhanixerver

Public exploits

SourceTitleDate
exploit-dbXerver HTTP Server 4.32 - Remote Denial of Service2009-09-18

References

→ the Explorer  ·  watch your stack  ·  NVD