CVE-2009-2309

Codice CMS 2 - SQL Injection via Tag Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2309. PoCs published by darkjoker.

AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in Codice CMS 2, allowing remote command execution by writing a malicious PHP shell to the server. It leverages a UNION-based SQL injection to create a shell.php file and then interacts with it to execute arbitrary commands.

Description

SQL injection vulnerability in index.php in Codice CMS 2 allows remote attackers to execute arbitrary SQL commands via the tag parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by darkjoker · perlwebappsphp
https://www.exploit-db.com/exploits/8272

This exploit targets a SQL injection vulnerability in Codice CMS 2, allowing remote command execution by writing a malicious PHP shell to the server. It leverages a UNION-based SQL injection to create a shell.php file and then interacts with it to execute arbitrary commands.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Codice CMS 2
No auth needed
Prerequisites: Target must be running Codice CMS 2 · Web server must have write permissions in the target directory
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34208
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/8272

Scores

EPSS 0.0091
EPSS Percentile 55.1%

Details

CWE
CWE-89
Status published
Products (1)
codice-cms/codice_cms 2
Published Jul 02, 2009
Tracked Since Feb 18, 2026