CVE-2009-1283

6.8
CVSS v2.0 Base Score
1.26%
LOW RiskEPSS (69th percentile)

glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privileges by obtaining the hash and using it in the glf_password cookie, aka "User Masquerading." NOTE: this can be leveraged with a separate SQL injection vulnerability to steal hashes.

Published: 4/9/2009
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

6.8

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

1.26%LOW Exploitation Risk
69th percentile

This vulnerability has a 1.26% probability of being exploited in the next 30 days, ranking higher than 69% of all scored CVEs.

CWE Classification

Advertisement