---
cve: "CVE-2009-2025"
severity: "LOW"
cvss: 3.1
epss: "2.6%"
vendor: "n/a"
kev: false
exploited: false
published: "2009-06-09 19:30:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-20T19:20:04+02:00"
---

# CVE-2009-2025

> 3.1 LOW · 🧪 PoC

## Beschreibung

admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) GROUPID, (3) GROUP, and (4) USERID cookies to certain values.

## Exploit-Evidenz

- [EDB-8903 — DM FileManager 3.9.2 - Insecure Cookie Handling](https://www.exploit-db.com/exploits/8903) ✅

## Referenzen

- <http://secunia.com/advisories/35167>
- <http://www.vupen.com/english/advisories/2009/1532>
- <https://www.exploit-db.com/exploits/8903>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2009-2025) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
