Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2009-4095

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

myPhile 1.2.1版本允许远程攻击者借助空密码,绕过身份认证。

AI Predicted 9.8 Difficulty: Easy EPSS 1.47% · P72
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2009-4095

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
myPhile 1.2.1 allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are obtained from third party information.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Companionway myPhile空口令认证绕过漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
myPhile 1.2.1版本允许远程攻击者借助空密码,绕过身份认证。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2009-4095

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-4095

登录查看更多情报信息。

Vendor Advisories for CVE-2009-4095 (3)

Other References for CVE-2009-4095 (1)

Same Patch Batch · n/a · 2009-11-27 · 21 CVEs total

CVE-2009-4092 Simplog "user.php" 跨站请求伪造漏洞
CVE-2009-4032 Cacti 跨站脚本漏洞
CVE-2009-4031 Linux kernel 输入验证错误漏洞
CVE-2009-4018 PHP proc_open()绕过safe_mode_protected_env_var限制漏洞
CVE-2009-4081 dstat不可信搜索路径参数权限提升漏洞
CVE-2009-4080 Sun OpenSolaris "ldap_cachemgr" 多个未明漏洞
CVE-2009-3894 Dag Wieers Dstat多个不可信的搜索路径参数权限提升漏洞
CVE-2009-3736 GNU Libtool libltdl ltdl.c本地权限提升漏洞
CVE-2009-4094 Designforjoomla 'eZine'远程文件包含漏洞
CVE-2009-4093 Simplog 多个跨站脚本攻击漏洞
CVE-2009-4082 Lanifex Outreach Project Tool 'index.php'远程文件包含漏洞
CVE-2009-4091 Simplog "comments.php" 权限许可和访问控制漏洞
CVE-2009-4090 telepark.wiki "ajax/addComment.php" 未限制文件上传漏洞
CVE-2009-4089 telepark.wiki 多个认证绕过漏洞
CVE-2009-4088 telepark.wiki 多个目录遍历漏洞
CVE-2009-4087 telepark.wiki "index.php" 跨站脚本攻击漏洞
CVE-2009-4086 Javascript Xerver HTTP Server跨站请求伪造漏洞
CVE-2009-4085 PHP Traverser 'mp3_id.php'文件包含漏洞
CVE-2009-4084 e107 SQL注入漏洞
CVE-2009-4083 e107 多个跨站脚本漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2009-4095

No comments yet


Leave a comment