CVE-2009-4657

Xerver 4.32 - Auth Bypass

Title source: llm
STIX 2.1

Description

The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting to the application on port 32123, as demonstrated by setting the action option to wizardStep1.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Dr_IDE · textdoswindows
https://www.exploit-db.com/exploits/9717

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9717
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/36454

Scores

EPSS 0.0141
EPSS Percentile 80.6%

Details

CWE
CWE-287
Status published
Products (1)
omidrouhani/xerver 4.32
Published Mar 03, 2010
Tracked Since Feb 18, 2026