CVE-2009-4447

Jax Guestbook 3.5.0 - Auth Bypass

Title source: llm

Description

Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbook.admin.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Sora · textwebappsphp
https://www.exploit-db.com/exploits/10626

Scores

EPSS 0.0253
EPSS Percentile 85.2%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

jax_scripts/jax_guestbook

Timeline

Published Dec 29, 2009
Tracked Since Feb 18, 2026