Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-2558

EPSS 2.65% · P86
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-2558

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
system/message.php in Admin News Tools 2.5 does not properly restrict access, which allows remote attackers to post news messages via a direct request.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Admin News Tools system/message.php权限许可和访问控制漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Admin News Tools 2.5版本的system/message.php中存在权限许可和访问控制漏洞。由于不严格的访问权限,远程攻击者借路径请求发布新闻消息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-2558

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-2558

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-07-21 · 12 CVEs total

CVE-2009-2565T-Okada Perl CGI's By Mrs. Shiromuku shiromuku(fs6)DIARY跨站脚本攻击漏洞
CVE-2009-2566TFM MMPlayer 缓冲区溢出漏洞
CVE-2009-2557Admin News Tools system/download.php目录遍历漏洞
CVE-2009-2559Wireshark 分析器IPMI 缓冲溢出和拒绝服务攻击漏洞
CVE-2009-2560Wireshark分析器IPMI多个未明拒绝服务攻击漏洞
CVE-2009-2561Wireshark 分析器sFlow 未明拒绝服务攻击漏洞
CVE-2009-2562Wireshark 分析器AFS 未明拒绝服务攻击漏洞
CVE-2009-2563Wireshark 分析器Infiniband 未明拒绝服务攻击漏洞
CVE-2009-2564NOS Microsystems getPlus下载管理器不安全文件权限漏洞
CVE-2009-2555Google V8 代码src/jsregexp.cc 堆缓冲溢出漏洞
CVE-2009-2556Google Chrome 权限扩大漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2009-2558

No comments yet


Leave a comment