CVE-2009-2111

DB Top Sites 1.0 - Remote Code Injection via add_reg.php URL and Location Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2111. PoCs published by SirGod.

AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in DB Top Sites v1.0 by injecting malicious PHP code into the 'location' field during user registration, allowing remote command execution via a crafted GET parameter.

Description

Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP code via a crafted (1) url and (2) location parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by SirGod · phpwebappsphp
https://www.exploit-db.com/exploits/8951

This exploit leverages a file inclusion vulnerability in DB Top Sites v1.0 by injecting malicious PHP code into the 'location' field during user registration, allowing remote command execution via a crafted GET parameter.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: DB Top Sites v1.0
No auth needed
Prerequisites: Target must have DB Top Sites v1.0 installed · Registration must be enabled on the target site
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8951
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35419
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/55119
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/51121

Scores

EPSS 0.0375
EPSS Percentile 88.5%

Details

CWE
CWE-94
Status published
Products (1)
jnmsolutions/db_top_sites 1.0
Published Jun 18, 2009
Tracked Since Feb 18, 2026