High severity7.5NVD Advisory· Published Mar 19, 2009· Updated Apr 23, 2026
CVE-2009-0964
CVE-2009-0964
Description
UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain passwords remotely without authentication.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.bugreport.ir/index_63.htmnvdBroken LinkExploit
- www.exploit-db.com/exploits/8226nvdExploitThird Party AdvisoryVDB Entry
- www.securityfocus.com/archive/1/501894/100/0/threadednvdBroken LinkThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/49279nvdThird Party AdvisoryVDB Entry
- osvdb.org/52804nvdBroken Link
- www.vupen.com/english/advisories/2009/0750nvdBroken Link
News mentions
0No linked articles in our index yet.