CVE-2009-4447: Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct requ
infovulnerability
security
Summary
Jax Guestbook version 3.5.0 has a vulnerability that allows attackers to skip authentication (the process of verifying who you are) and change administrator settings by directly accessing the admin/guestbook.admin.php file. This is classified as a CWE-287 weakness, meaning the software's authentication mechanism is broken.
Vulnerability Details
CVSS Score
7.5
EPSS (30-day exploit probability)
EPSS: 2.5%
Classification
Attack SophisticationTrivial
Original source: https://nvd.nist.gov/vuln/detail/CVE-2009-4447
First tracked: February 15, 2026 at 08:43 PM
Classified by LLM (prompt v3) · confidence: 95%