CVE-2009-2111
DB Top Sites 1.0 - Remote Code Injection via add_reg.php URL and Location Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2111. PoCs published by SirGod.
AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in DB Top Sites v1.0 by injecting malicious PHP code into the 'location' field during user registration, allowing remote command execution via a crafted GET parameter.
Description
Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP code via a crafted (1) url and (2) location parameter.
Exploits (1)
This exploit leverages a file inclusion vulnerability in DB Top Sites v1.0 by injecting malicious PHP code into the 'location' field during user registration, allowing remote command execution via a crafted GET parameter.