CVE-2009-2276
Vote For Us Extension < 1.0.1 - SQL Injection via 'out' Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2276. PoCs published by Dante90.
AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in PunBB VoteForUs.php OUT Mod <= v1.0.1 by brute-forcing the password hash of a specified user ID through time-based SQL queries.
Description
SQL injection vulnerability in voteforus.php in the Vote For Us extension 1.0.1 and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the out parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Dante90 · perlwebappsphp
https://www.exploit-db.com/exploits/9058
This Perl script exploits a blind SQL injection vulnerability in PunBB VoteForUs.php OUT Mod <= v1.0.1 by brute-forcing the password hash of a specified user ID through time-based SQL queries.
Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target:
PunBB VoteForUs.php OUT Mod <= v1.0.1
No auth needed
Prerequisites:
Target URL with vulnerable PunBB VoteForUs.php installation · User ID to extract password hash for
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (1)
Core 1
Core References
Exploit, Third Party Advisory exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/9058
Scores
EPSS
0.0092
EPSS Percentile
55.6%
Details
CWE
CWE-89
Status
published
Products (2)
biglle/vote_for_us_extension
1.0
biglle/vote_for_us_extension
< 1.0.1
Published
Jul 01, 2009
Tracked Since
Feb 18, 2026