CVE-2009-2276

Vote For Us Extension < 1.0.1 - SQL Injection via 'out' Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2276. PoCs published by Dante90.

AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in PunBB VoteForUs.php OUT Mod <= v1.0.1 by brute-forcing the password hash of a specified user ID through time-based SQL queries.

Description

SQL injection vulnerability in voteforus.php in the Vote For Us extension 1.0.1 and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the out parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Dante90 · perlwebappsphp
https://www.exploit-db.com/exploits/9058

This Perl script exploits a blind SQL injection vulnerability in PunBB VoteForUs.php OUT Mod <= v1.0.1 by brute-forcing the password hash of a specified user ID through time-based SQL queries.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: PunBB VoteForUs.php OUT Mod <= v1.0.1
No auth needed
Prerequisites: Target URL with vulnerable PunBB VoteForUs.php installation · User ID to extract password hash for
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9058

Scores

EPSS 0.0092
EPSS Percentile 55.6%

Details

CWE
CWE-89
Status published
Products (2)
biglle/vote_for_us_extension 1.0
biglle/vote_for_us_extension < 1.0.1
Published Jul 01, 2009
Tracked Since Feb 18, 2026