Description
The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting to the application on port 32123, as demonstrated by setting the action option to wizardStep1.
Published: 2010-03-03
Score: 7.5 High
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2009-4622 The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting to the application on port 32123, as demonstrated by setting the action option to wizardStep1.
History

No history.

Subscriptions

Omidrouhani Xerver
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T07:08:38.267Z

Reserved: 2010-03-03T00:00:00.000Z

Link: CVE-2009-4657

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-03-03T20:30:00.400

Modified: 2026-04-29T01:13:23.040

Link: CVE-2009-4657

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses