← Back to browse · API

CVE-2009-2168

Severity
CRITICAL
CVSS
9.8
EPSS
0.11776
Risk score
43.32
CISA KEV
No
PoC
No
Published
2009-06-22
Modified
2025-01-21
First seen
2026-08-07
Aliases
EUVD-2009-2164, GHSA-H2HC-3HMW-FMQ5
Products
n/a:n/a n/a
Sources
euvd EUVD-2009-2164

Description

cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit when the supplied credentials are incorrect, which allows remote attackers to bypass authentication by providing arbitrary username and password parameters.

References