CVE-2009-2786

PunBB Reputation <2.2.4 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in reputation.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the poster parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Dante90 · perlwebappsphp
https://www.exploit-db.com/exploits/9289

Scores

EPSS 0.0024
EPSS Percentile 47.6%

Details

CWE
CWE-89
Status published
Products (3)
reputation/reputation 2.0.4
reputation/reputation 2.2.3
reputation/reputation < 2.2.4
Published Aug 17, 2009
Tracked Since Feb 18, 2026