{"api_version":"1","generated_at":"2026-07-23T11:37:29+00:00","cve":"CVE-2009-1767","urls":{"html":"https://cve.report/CVE-2009-1767","api":"https://cve.report/api/cve/CVE-2009-1767.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-1767","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-1767"},"summary":{"title":"CVE-2009-1767","description":"admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-05-22 18:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/35090","name":"http://secunia.com/advisories/35090","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Template Monster Clone \"edituser.php\" Security Bypass Vulnerability - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/34977","name":"http://www.securityfocus.com/bid/34977","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Template Monster Clone 'edituser.php' Remote Password Change Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/50561","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/50561","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/8691","name":"https://www.exploit-db.com/exploits/8691","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"2daybiz Template Monster Clone (edituser.php)  Change Pass Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-1767","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-1767","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"1767","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"2daybiz","cpe5":"template_monster_clone","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:27:53.673Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"34977","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/34977"},{"name":"35090","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/35090"},{"name":"8691","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/8691"},{"name":"tmc-edituser-security-bypass(50561)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/50561"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-05-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"34977","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/34977"},{"name":"35090","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/35090"},{"name":"8691","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/8691"},{"name":"tmc-edituser-security-bypass(50561)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/50561"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-1767","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"34977","refsource":"BID","url":"http://www.securityfocus.com/bid/34977"},{"name":"35090","refsource":"SECUNIA","url":"http://secunia.com/advisories/35090"},{"name":"8691","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/8691"},{"name":"tmc-edituser-security-bypass(50561)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/50561"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-1767","datePublished":"2009-05-22T18:00:00.000Z","dateReserved":"2009-05-22T00:00:00.000Z","dateUpdated":"2024-08-07T05:27:53.673Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-05-22 18:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:2daybiz:template_monster_clone:-:*:*:*:*:*:*:*","matchCriteriaId":"E22BADE3-F86E-492F-9E7B-0F92B6D8C2BE"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"1767","Ordinal":"1","Title":"CVE-2009-1767","CVE":"CVE-2009-1767","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"1767","Ordinal":"1","NoteData":"admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.","Type":"Description","Title":"CVE-2009-1767"},{"CveYear":"2009","CveId":"1767","Ordinal":"2","NoteData":"2009-05-22","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"1767","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}