CVE-2009-4657
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 2.2%
from disclosure to weapon0 days
Published on NVDMar 3
1st PoCSep 18
exploitation probability
2.2%top 19% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting to the application on port 32123, as demonstrated by setting the action option to wizardStep1.
Affected products
n/a · n/apublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/9717cve_referencewww.exploit-db.com/exploits/9717unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.