CVE-2009-1525
CVE-2009-1525 is a high-severity vulnerability in Directadmin with a CVSS 2.0 base score of 8.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-20.
Key facts
- Severity: High (CVSS 2.0 base score 8.5)
- EPSS exploit prediction: 2% (83rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-20
- Affected product: Directadmin
- Published:
- Last modified:
Description
CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metacharacters in the name parameter during a restore action.
Frequently asked questions
- What is CVE-2009-1525?
- CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metacharacters in the name parameter during a restore action.
- How severe is CVE-2009-1525?
- CVE-2009-1525 has a CVSS 2.0 base score of 8.5, rated high severity.
- Is CVE-2009-1525 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (83rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2009-1525?
- CVE-2009-1525 affects Directadmin. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2009-1525?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2009-1525 published?
- CVE-2009-1525 was published on 2009-05-05 and last updated on 2026-06-16.
References
- http://archives.neohapsis.com/archives/fulldisclosure/2009-04/0228.html
- http://osvdb.org/54015
- http://secunia.com/advisories/34861
- http://www.directadmin.com/features.php?id=968
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50167
Affected products (1)
- cpe:2.3:a:directadmin:directadmin:*:*:*:*:*:*:*:*
More vulnerabilities in Directadmin
- CVE-2017-18045 — Critical (CVSS 9.8): JBMC DirectAdmin before 1.52, when the email_ftp_password_change setting is nonzero, allows remote attackers to obtain…
- CVE-2019-9625 — High (CVSS 8.8): JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.
- CVE-2025-56551 — High (CVSS 8.2): An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate…
- CVE-2009-1526 — Medium (CVSS 6.9): JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an…
- CVE-2007-1926 — Medium (CVSS 6.8): Cross-site scripting (XSS) vulnerability in JBMC Software DirectAdmin before 1.293 does not properly display log files,…
- CVE-2019-11193 — Medium (CVSS 6.1): The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and…
All CVEs affecting Directadmin →
Other CWE-20 (Improper Input Validation) vulnerabilities
- CVE-2026-48056 — Critical (CVSS 10.0): Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0…
- CVE-2026-33267 — Critical (CVSS 10.0): Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0…
- CVE-2026-47668 — Critical (CVSS 10.0): DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST…
- CVE-2026-16117 — Critical (CVSS 10.0): Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix…
- CVE-2026-48316 — Critical (CVSS 10.0): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could…
- CVE-2026-48281 — Critical (CVSS 10.0): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could…
Browse all CWE-20 (Improper Input Validation) vulnerabilities →