{"api_version":"1","generated_at":"2026-07-23T11:02:09+00:00","cve":"CVE-2009-0962","urls":{"html":"https://cve.report/CVE-2009-0962","api":"https://cve.report/api/cve/CVE-2009-0962.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-0962","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-0962"},"summary":{"title":"CVE-2009-0962","description":"Unspecified vulnerability in Futomi's CGI Cafe MP Form Mail CGI eCommerce 1.3.0 and earlier, and CGI Professional 3.2.2 and earlier, allows remote attackers to gain administrative privileges via unknown attack vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-03-19 00:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://osvdb.org/52527","name":"http://osvdb.org/52527","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/34071","name":"http://www.securityfocus.com/bid/34071","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Futomi's CGI Cafe MP Form Mail CGI Unspecified Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000014.html","name":"http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000014.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49180","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49180","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://jvn.jp/en/jp/JVN84899898/index.html","name":"http://jvn.jp/en/jp/JVN84899898/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"JVN#84899898: MP Form Mail CGI vulnerability allows third party to gain administrative privileges","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://www.futomi.com/library/info/2009/20090310.html","name":"http://www.futomi.com/library/info/2009/20090310.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MP Form Mail CGI Professional版・eCommerce版（旧バージョン） 新バージョンの提供について- futomi's CGI Cafe","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/34197","name":"http://secunia.com/advisories/34197","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Futomi's CGI Cafe MP Form Mail CGI Security Bypass - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49179","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49179","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-0962","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-0962","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"962","vulnerable":"1","versionEndIncluding":"1.3.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"futomi","cpe5":"mp_form_mail_cgi","cpe6":"*","cpe7":"-","cpe8":"ecommerce","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"962","vulnerable":"1","versionEndIncluding":"3.2.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"futomi","cpe5":"mp_form_mail_cgi","cpe6":"*","cpe7":"-","cpe8":"pro","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:57:17.203Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"JVNDB-2009-000014","tags":["third-party-advisory","x_refsource_JVNDB","x_transferred"],"url":"http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000014.html"},{"name":"52527","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/52527"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.futomi.com/library/info/2009/20090310.html"},{"name":"mpformmailcgi-pro-unspecified-sec-bypass(49180)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49180"},{"name":"34197","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/34197"},{"name":"34071","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/34071"},{"name":"mpformmailcgi-ecom-unspecified-sec-bypass(49179)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49179"},{"name":"JVN#84899898","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/en/jp/JVN84899898/index.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-03-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in Futomi's CGI Cafe MP Form Mail CGI eCommerce 1.3.0 and earlier, and CGI Professional 3.2.2 and earlier, allows remote attackers to gain administrative privileges via unknown attack vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"JVNDB-2009-000014","tags":["third-party-advisory","x_refsource_JVNDB"],"url":"http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000014.html"},{"name":"52527","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/52527"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.futomi.com/library/info/2009/20090310.html"},{"name":"mpformmailcgi-pro-unspecified-sec-bypass(49180)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49180"},{"name":"34197","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/34197"},{"name":"34071","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/34071"},{"name":"mpformmailcgi-ecom-unspecified-sec-bypass(49179)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49179"},{"name":"JVN#84899898","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/en/jp/JVN84899898/index.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-0962","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in Futomi's CGI Cafe MP Form Mail CGI eCommerce 1.3.0 and earlier, and CGI Professional 3.2.2 and earlier, allows remote attackers to gain administrative privileges via unknown attack vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"JVNDB-2009-000014","refsource":"JVNDB","url":"http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000014.html"},{"name":"52527","refsource":"OSVDB","url":"http://osvdb.org/52527"},{"name":"http://www.futomi.com/library/info/2009/20090310.html","refsource":"CONFIRM","url":"http://www.futomi.com/library/info/2009/20090310.html"},{"name":"mpformmailcgi-pro-unspecified-sec-bypass(49180)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49180"},{"name":"34197","refsource":"SECUNIA","url":"http://secunia.com/advisories/34197"},{"name":"34071","refsource":"BID","url":"http://www.securityfocus.com/bid/34071"},{"name":"mpformmailcgi-ecom-unspecified-sec-bypass(49179)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49179"},{"name":"JVN#84899898","refsource":"JVN","url":"http://jvn.jp/en/jp/JVN84899898/index.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-0962","datePublished":"2009-03-19T00:00:00.000Z","dateReserved":"2009-03-18T00:00:00.000Z","dateUpdated":"2024-08-07T04:57:17.203Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-03-19 00:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:futomi:mp_form_mail_cgi:*:-:ecommerce:*:*:*:*:*","versionEndIncluding":"1.3.0","matchCriteriaId":"FDEAB009-89A1-401A-80D0-6F9E14296FC5"},{"vulnerable":true,"criteria":"cpe:2.3:a:futomi:mp_form_mail_cgi:*:-:pro:*:*:*:*:*","versionEndIncluding":"3.2.2","matchCriteriaId":"D5B8074E-F12B-48C6-85A0-9920B4CE19D0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"962","Ordinal":"1","Title":"CVE-2009-0962","CVE":"CVE-2009-0962","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"962","Ordinal":"1","NoteData":"Unspecified vulnerability in Futomi's CGI Cafe MP Form Mail CGI eCommerce 1.3.0 and earlier, and CGI Professional 3.2.2 and earlier, allows remote attackers to gain administrative privileges via unknown attack vectors.","Type":"Description","Title":"CVE-2009-0962"},{"CveYear":"2009","CveId":"962","Ordinal":"2","NoteData":"2009-03-18","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"962","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}