CVE-2009-2110

DB Top Sites 1.0 - Path Traversal via u Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2110. PoCs published by SirGod.

AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in DB Top Sites v1.0. The vulnerable code in index.php allows arbitrary file inclusion via the 'u' parameter, enabling attackers to read sensitive files like BOOTSECT.BAK.

Description

Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the u parameter to (1) full.php, (2) index.php, and (3) contact.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by SirGod · textwebappsphp
https://www.exploit-db.com/exploits/8952

This exploit demonstrates a Local File Inclusion (LFI) vulnerability in DB Top Sites v1.0. The vulnerable code in index.php allows arbitrary file inclusion via the 'u' parameter, enabling attackers to read sensitive files like BOOTSECT.BAK.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: DB Top Sites v1.0
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/55118
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8952
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/51120
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35419
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/55117
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/55116

Scores

EPSS 0.0845
EPSS Percentile 94.3%

Details

CWE
CWE-22
Status published
Products (1)
jnmsolutions/db_top_sites 1.0
Published Jun 18, 2009
Tracked Since Feb 18, 2026