CVE-2009-1604: High severity Limesurvey LimeSurvey vulnerability
Published May 11, 2009
·Updated
Unspecified vulnerability in LimeSurvey before 1.82 allows remote attackers to execute commands and obtain sensitive data via unknown attack vectors related to /admin/remotecontrol/.
Affected Software
5 affected components
Limesurvey LimeSurvey=1.80
Limesurvey LimeSurvey=1.80-rc4
Limesurvey LimeSurvey=1.80\+
Limesurvey LimeSurvey=1.81
Limesurvey LimeSurvey=1.81\+
Remediation
Patch Available
Patch Available
Event History
May 11, 2009
CVE Published
via MITRE·07:28 PM
Data Sourced
via MITRE·07:28 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1604?
CVE-2009-1604 is considered a high severity vulnerability that allows remote command execution.
2
How do I fix CVE-2009-1604?
To fix CVE-2009-1604, upgrade LimeSurvey to version 1.82 or later.
3
What versions of LimeSurvey are affected by CVE-2009-1604?
CVE-2009-1604 affects LimeSurvey versions 1.80 and 1.81, including their variants.
4
What type of attacks does CVE-2009-1604 enable?
CVE-2009-1604 enables remote attackers to execute arbitrary commands on the server.
5
How can CVE-2009-1604 impact sensitive data?
CVE-2009-1604 can lead to unauthorized access to sensitive data if exploited.