High severity7.5NVD Advisory· Published Mar 19, 2009· Updated Jun 16, 2026
CVE-2009-0964
CVE-2009-0964
Description
UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain passwords remotely without authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
6- www.bugreport.ir/index_63.htmnvdBroken LinkExploit
- www.exploit-db.com/exploits/8226nvdExploitThird Party AdvisoryVDB Entry
- www.securityfocus.com/archive/1/501894/100/0/threadednvdBroken LinkThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/49279nvdThird Party AdvisoryVDB Entry
- osvdb.org/52804nvdBroken Link
- www.vupen.com/english/advisories/2009/0750nvdBroken Link
News mentions
0No linked articles in our index yet.