CVE-2009-1949 describes an information disclosure vulnerability in Unclassified NewsBoard (UNB) version 1.6.4. Remote attackers can directly request the import_wbb1.php file, which then reveals the server's installation path in an error message. This vulnerability has a high severity CVSS score of 7.8, indicating a network-based attack with low complexity and a critical impact on confidentiality, allowing unauthorized access to sensitive system information. There is no evidence of active exploitation, nor are there Metasploit or Nuclei modules, though an ExploitDB entry exists. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6.4CPE matchmatch criteria | cpe:2.3:a:unclassified:newsboard:1.6.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.