CVE-2009-2945 describes a vulnerability in Stanford University WebAuth versions 3.5.5, 3.6.0, and 3.6.1, where the weblogin/login.fcgi script could expose user passwords. This occurred when a POST request was converted to a GET request, causing passwords to be placed in the URL. Attackers could then discover these passwords by accessing web-server logs (access or Referer) or the user's browser history. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity and partial confidentiality impact, requiring no authentication. The primary impact is the unauthorized disclosure of sensitive information (passwords). There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.5.5CPE matchmatch criteria | cpe:2.3:a:stanford:webauth:3.5.5:*:*:*:*:*:*:* | ||
3.6.0CPE matchmatch criteria | cpe:2.3:a:stanford:webauth:3.6.0:*:*:*:*:*:*:* | ||
3.6.1CPE matchmatch criteria | cpe:2.3:a:stanford:webauth:3.6.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.