CVE-2009-4657
Last modified
CVE-2009-4657 is a vulnerability of currently unknown severity. The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting to the application on port 32123, as demonstrated by setting the action option to wizardStep1.. EPSS estimates a 2.17% chance of exploitation in the next 30 days.
Description
The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting to the application on port 32123, as demonstrated by setting the action option to wizardStep1.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Omidrouhani | Xerver | 4.32 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-4657?
How severe is CVE-2009-4657?
How do I fix CVE-2009-4657?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-4651Multiple cross-site scripting (XSS) vulnerabilities in the W…
- CVE-2009-4652The (1) Conn_GetCipherInfo and (2) Conn_UsesSSL functions in…
- CVE-2009-4653Stack-based buffer overflow in the dhost module in Novell eD…
- CVE-2009-4654Stack-based buffer overflow in the dhost module in Novell eD…
- CVE-2009-4655The dhost web service in Novell eDirectory 8.8.5 uses a pred…
- CVE-2009-4656Stack-based buffer overflow in E-Soft DJ Studio Pro 4.2 incl…
- CVE-2009-4658Xerver 4.32 allows remote authenticated users to cause a den…
- CVE-2009-4659Unspecified vulnerability in MP3-Cutter Ease Audio Cutter 1.…
- CVE-2009-4660Stack-based buffer overflow in the AntServer Module (AntServ…
- CVE-2009-4661Multiple buffer overflows in BigAnt Server 2.50 SP6 and earl…
- CVE-2009-4662Cross-site scripting (XSS) vulnerability in the WebAccess co…
- CVE-2009-4663Heap-based buffer overflow in the Quiksoft EasyMail Objects …
Are you affected by CVE-2009-4657?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
